This is an automated email from the ASF dual-hosted git repository.
yesamer pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/incubator-kie.git
The following commit(s) were added to refs/heads/main by this push:
new eadc587069b Upgrade Spring Boot from 4.0.8 to 4.1.1 (#7128)
eadc587069b is described below
commit eadc587069b369733c7c879929634670d5854b55
Author: ANN JOY <[email protected]>
AuthorDate: Fri Sep 25 20:26:44 2026 +0530
Upgrade Spring Boot from 4.0.8 to 4.1.1 (#7128)
* Upgrade Spring Boot from 4.0.8 to 4.1.1
* fix(springboot): pin Netty to 4.2.18 and fix BeansCreationSanityTest
after Spring Boot 4.1.1 upgrade
- Bump version.io.netty from 4.2.17.Final to 4.2.18.Final in
kogito-spring-boot-bom
- Add spring.cloud.kubernetes.discovery.enabled=false to test
application.properties
to disable Fabric8InformerAutoConfiguration (new in
spring-cloud-kubernetes-fabric8
5.0.2) which attempts eager namespace resolution and API server
connection outside
a real cluster environment
* Update BOM comments to reference Spring Boot 4.1.1
* docs(kubernetes): add spring.cloud.kubernetes.discovery.enabled=false to
test setup guidance
* fix(bom): align fabric8 to 7.4.1 as declared by
spring-cloud-kubernetes-fabric8 5.0.2
* Improve fabric8 version pin comment for traceability
Expand the comment on version.io.fabric8 in kogito-spring-boot-bom to:
- Explain that this overrides kie-parent's 7.3.1
- Show that 5.0.2 comes from
spring-cloud-dependencies:${version.org.springframework.cloud}
- Add maintenance note to re-check fabric8 when upgrading
version.org.springframework.cloud
---------
Co-authored-by: athirakm <[email protected]>
---
kogito-springboot/addons/kubernetes/README.md | 9 ++++++++-
.../src/test/resources/application.properties | 3 ++-
kogito-springboot/bom/pom.xml | 22 +++++++++++++---------
optaplanner-build/optaplanner-build-parent/pom.xml | 2 +-
4 files changed, 24 insertions(+), 12 deletions(-)
diff --git a/kogito-springboot/addons/kubernetes/README.md
b/kogito-springboot/addons/kubernetes/README.md
index 6b7bf468606..ec67e691266 100644
--- a/kogito-springboot/addons/kubernetes/README.md
+++ b/kogito-springboot/addons/kubernetes/README.md
@@ -34,9 +34,16 @@ When using this add-on is important to set the following
properties in your test
```properties
spring.main.cloud-platform=KUBERNETES
spring.cloud.bootstrap.enabled=true
+# Required when running tests outside a real Kubernetes cluster (Spring Cloud
Kubernetes 5.0.2+).
+# Fabric8InformerAutoConfiguration performs eager namespace resolution and API
server connection
+# on startup. Without this property, ApplicationContext loading fails with an
Unauthorized (401)
+# error when no valid cluster credentials are present.
+spring.cloud.kubernetes.discovery.enabled=false
```
-This will guarantee that he right `KubernetesClient` bean is created for you.
See more at [Kubernetes Ecosystem
Awareness](https://docs.spring.io/spring-cloud-kubernetes/docs/current/reference/html/#kubernetes-ecosystem-awareness).
+This will guarantee that the right `KubernetesClient` bean is created for you.
See more at [Kubernetes Ecosystem
Awareness](https://docs.spring.io/spring-cloud-kubernetes/docs/current/reference/html/#kubernetes-ecosystem-awareness).
+
+> **Note:** `spring.cloud.kubernetes.discovery.enabled=false` is a
**test-only** setting. Do not add it to your production
`application.properties` as it disables Kubernetes service discovery at runtime.
## Caching
diff --git
a/kogito-springboot/addons/kubernetes/src/test/resources/application.properties
b/kogito-springboot/addons/kubernetes/src/test/resources/application.properties
index 2cebc054ae9..ded3cfb5467 100644
---
a/kogito-springboot/addons/kubernetes/src/test/resources/application.properties
+++
b/kogito-springboot/addons/kubernetes/src/test/resources/application.properties
@@ -18,4 +18,5 @@
#
spring.main.cloud-platform=KUBERNETES
-spring.cloud.bootstrap.enabled=true
\ No newline at end of file
+spring.cloud.bootstrap.enabled=true
+spring.cloud.kubernetes.discovery.enabled=false
\ No newline at end of file
diff --git a/kogito-springboot/bom/pom.xml b/kogito-springboot/bom/pom.xml
index d4b241226cb..2e2ce45d02a 100644
--- a/kogito-springboot/bom/pom.xml
+++ b/kogito-springboot/bom/pom.xml
@@ -34,20 +34,24 @@
<properties>
<!-- Used to define which poms are allowed to have dependencyManagement
sections. This is to enforce the convention that only the root pom should have
dependencyManagement, and all other poms should inherit from it. -->
<allowedPomsList>org.kie.kogito:kogito-spring-boot-bom</allowedPomsList>
- <!-- Aligned with Spring Boot Cloud (spring-cloud-kubernetes-fabric8 5.0.1
declares fabric8 7.4.0) -->
- <version.io.fabric8>7.4.0</version.io.fabric8>
- <version.io.netty>4.2.17.Final</version.io.netty>
+ <!-- Overrides kie-parent fabric8 7.3.1 to align with Spring Cloud.
+ spring-cloud-dependencies:${version.org.springframework.cloud} imports
+ spring-cloud-kubernetes-fabric8:5.0.2, which requires io.fabric8
7.4.1.
+ When upgrading version.org.springframework.cloud, re-check the
fabric8 version
+ declared by spring-cloud-kubernetes-fabric8 in the new
spring-cloud-dependencies BOM. -->
+ <version.io.fabric8>7.4.1</version.io.fabric8>
+ <version.io.netty>4.2.18.Final</version.io.netty>
<version.jakarta.servlet>6.0.0</version.jakarta.servlet>
<version.org.springdoc>2.8.13</version.org.springdoc>
<version.org.springframework>7.0.9</version.org.springframework>
- <version.org.springframework.boot>4.0.8</version.org.springframework.boot>
-
<version.org.springframework.cloud>2025.1.1</version.org.springframework.cloud>
- <!-- CVE-2026-49844: Spring Boot 4.0.7 sets log4j2.version=2.25.4 which is
vulnerable.
+ <version.org.springframework.boot>4.1.1</version.org.springframework.boot>
+
<version.org.springframework.cloud>2025.1.2</version.org.springframework.cloud>
+ <!-- CVE-2026-49844: Spring Boot 4.1.1 sets log4j2.version=2.25.5 which is
vulnerable.
Override the version property inherited from kie-parent to 2.26.1
(minimum 2.25.5).
https://logging.apache.org/security.html#CVE-2026-49844 -->
<version.org.apache.logging.log4j>2.26.1</version.org.apache.logging.log4j>
<!-- CVE-2026-59889: force-pin jackson-databind to 3.1.6.
- spring-boot-dependencies:4.0.8 carries the vulnerable
jackson-databind:3.1.5.
+ spring-boot-dependencies:4.1.1 carries the vulnerable
jackson-databind:3.1.5.
Remove this pin once spring-boot-dependencies imports
jackson-databind >= 3.1.6. -->
<version.tools.jackson.core>3.1.6</version.tools.jackson.core>
<!-- Framework-specific pins moved out of kie-parent: only this tree
declares these artifacts. -->
@@ -85,8 +89,8 @@
<type>pom</type>
<scope>import</scope>
</dependency>
- <!-- CVE fix: spring-boot-dependencies:4.0.x imports
mongodb-driver-bom:5.6.5 which pins
- mongodb-driver-core and bson to 5.6.5. Override to match
mongodb-driver-sync:5.9.2.
+ <!-- CVE fix: spring-boot-dependencies:4.1.1 imports
mongodb-driver-bom:5.8.1 which pins
+ mongodb-driver-core and bson to 5.8.1. Override to match
mongodb-driver-sync:5.9.2.
https://jira.mongodb.org/browse/JAVA-6266 -->
<dependency>
<groupId>org.mongodb</groupId>
diff --git a/optaplanner-build/optaplanner-build-parent/pom.xml
b/optaplanner-build/optaplanner-build-parent/pom.xml
index 06bce776361..48262397c66 100644
--- a/optaplanner-build/optaplanner-build-parent/pom.xml
+++ b/optaplanner-build/optaplanner-build-parent/pom.xml
@@ -65,7 +65,7 @@
<!-- CVE-2026-56624: Apache MINA SSHD fixed version -->
<version.org.apache.sshd>2.19.0</version.org.apache.sshd>
<version.org.springframework>7.0.9</version.org.springframework>
- <version.org.springframework.boot>4.0.8</version.org.springframework.boot>
+ <version.org.springframework.boot>4.1.1</version.org.springframework.boot>
<version.com.fasterxml.jackson.databind>2.22.2</version.com.fasterxml.jackson.databind>
<!--
************************************************************************ -->
<!-- Plugins -->
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]