Skip to content

Releases: OpenIdentityPlatform/commons

3.1.0

14 Apr 09:09

Choose a tag to compare

What's Changed

  • Update build.yml add JDK 26 support by @vharseko in #166
  • Fix NPE in ServletJwtSessionModuleTest due to commented-out mock stub by @Copilot in #168
  • CVE-2025-67030 Plexus-Utils has a Directory Traversal vulnerability in its extractFile method by @dependabot[bot] in #167
  • chore: bump actions/checkout to v6 and actions/cache to v5 by @Copilot in #170
  • fix: correct issuedAtTime in JWT cool-off period test by @Copilot in #171
  • Extract embedded POM from JAR during install/deploy instead of generating minimal stub by @Copilot in #169
  • [OpenIdentityPlatform/OpenAM#980] Resolve duplicate dependencies by @maximthomas in #172
  • CVE-2026-32588 CVE-2026-27314 Apache Cassandra has an authenticated DoS over CQL + is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticator by @dependabot[bot] in #173

New Contributors

  • @Copilot made their first contribution in #168

Full Changelog: 3.0.4...3.1.0

3.0.4

22 Mar 17:49

Choose a tag to compare

What's Changed

Full Changelog: 3.0.3...3.0.4

3.0.3

09 Mar 11:12

Choose a tag to compare

What's Changed

Full Changelog: 3.0.2...3.0.3

3.0.2

11 Dec 08:59

Choose a tag to compare

What's Changed

Full Changelog: 3.0.1...3.0.2

3.0.1

06 Nov 14:13

Choose a tag to compare

What's Changed

Full Changelog: 2.4.1...3.0.1

2.4.1

04 Sep 08:43

Choose a tag to compare

What's Changed

  • CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties by @maximthomas in #153
  • move javax.version to servlet-api.version property in maven by @maximthomas in #152

Full Changelog: 2.4.0...2.4.1

2.4.0

15 Jul 10:35

Choose a tag to compare

What's Changed

Full Changelog: 2.3.0...2.4.0

2.3.0

19 Jun 12:57

Choose a tag to compare

What's Changed

Full Changelog: 2.2.4...2.3.0

2.2.4

17 Mar 11:22

Choose a tag to compare

What's Changed

  • Bump org.springframework:spring-core from 6.0.16 to 6.1.14 in /commons/httpdump by @dependabot in #131
  • Fix UI tests with Puppeteer in Linux by @maximthomas in #134
  • Docs: get release version from GitHub release by @maximthomas in #136

Full Changelog: 2.2.3...2.2.4

2.2.3

08 Nov 10:07

Choose a tag to compare

What's Changed

Full Changelog: 2.2.2...2.2.3