This is an automated email from the ASF dual-hosted git repository.

yesamer pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/incubator-kie.git


The following commit(s) were added to refs/heads/main by this push:
     new eadc587069b Upgrade Spring Boot from 4.0.8 to 4.1.1 (#7128)
eadc587069b is described below

commit eadc587069b369733c7c879929634670d5854b55
Author: ANN JOY <[email protected]>
AuthorDate: Fri Sep 25 20:26:44 2026 +0530

    Upgrade Spring Boot from 4.0.8 to 4.1.1 (#7128)
    
    * Upgrade Spring Boot from 4.0.8 to 4.1.1
    
    * fix(springboot): pin Netty to 4.2.18 and fix BeansCreationSanityTest 
after Spring Boot 4.1.1 upgrade
    
    - Bump version.io.netty from 4.2.17.Final to 4.2.18.Final in 
kogito-spring-boot-bom
    - Add spring.cloud.kubernetes.discovery.enabled=false to test 
application.properties
      to disable Fabric8InformerAutoConfiguration (new in 
spring-cloud-kubernetes-fabric8
      5.0.2) which attempts eager namespace resolution and API server 
connection outside
      a real cluster environment
    
    * Update BOM comments to reference Spring Boot 4.1.1
    
    * docs(kubernetes): add spring.cloud.kubernetes.discovery.enabled=false to 
test setup guidance
    
    * fix(bom): align fabric8 to 7.4.1 as declared by 
spring-cloud-kubernetes-fabric8 5.0.2
    
    * Improve fabric8 version pin comment for traceability
    
    Expand the comment on version.io.fabric8 in kogito-spring-boot-bom to:
    - Explain that this overrides kie-parent's 7.3.1
    - Show that 5.0.2 comes from 
spring-cloud-dependencies:${version.org.springframework.cloud}
    - Add maintenance note to re-check fabric8 when upgrading 
version.org.springframework.cloud
    
    ---------
    
    Co-authored-by: athirakm <[email protected]>
---
 kogito-springboot/addons/kubernetes/README.md      |  9 ++++++++-
 .../src/test/resources/application.properties      |  3 ++-
 kogito-springboot/bom/pom.xml                      | 22 +++++++++++++---------
 optaplanner-build/optaplanner-build-parent/pom.xml |  2 +-
 4 files changed, 24 insertions(+), 12 deletions(-)

diff --git a/kogito-springboot/addons/kubernetes/README.md 
b/kogito-springboot/addons/kubernetes/README.md
index 6b7bf468606..ec67e691266 100644
--- a/kogito-springboot/addons/kubernetes/README.md
+++ b/kogito-springboot/addons/kubernetes/README.md
@@ -34,9 +34,16 @@ When using this add-on is important to set the following 
properties in your test
 ```properties
 spring.main.cloud-platform=KUBERNETES
 spring.cloud.bootstrap.enabled=true
+# Required when running tests outside a real Kubernetes cluster (Spring Cloud 
Kubernetes 5.0.2+).
+# Fabric8InformerAutoConfiguration performs eager namespace resolution and API 
server connection
+# on startup. Without this property, ApplicationContext loading fails with an 
Unauthorized (401)
+# error when no valid cluster credentials are present.
+spring.cloud.kubernetes.discovery.enabled=false
 ```
 
-This will guarantee that he right `KubernetesClient` bean is created for you. 
See more at [Kubernetes Ecosystem 
Awareness](https://docs.spring.io/spring-cloud-kubernetes/docs/current/reference/html/#kubernetes-ecosystem-awareness).
+This will guarantee that the right `KubernetesClient` bean is created for you. 
See more at [Kubernetes Ecosystem 
Awareness](https://docs.spring.io/spring-cloud-kubernetes/docs/current/reference/html/#kubernetes-ecosystem-awareness).
+
+> **Note:** `spring.cloud.kubernetes.discovery.enabled=false` is a 
**test-only** setting. Do not add it to your production 
`application.properties` as it disables Kubernetes service discovery at runtime.
 
 ## Caching
 
diff --git 
a/kogito-springboot/addons/kubernetes/src/test/resources/application.properties 
b/kogito-springboot/addons/kubernetes/src/test/resources/application.properties
index 2cebc054ae9..ded3cfb5467 100644
--- 
a/kogito-springboot/addons/kubernetes/src/test/resources/application.properties
+++ 
b/kogito-springboot/addons/kubernetes/src/test/resources/application.properties
@@ -18,4 +18,5 @@
 #
 
 spring.main.cloud-platform=KUBERNETES
-spring.cloud.bootstrap.enabled=true
\ No newline at end of file
+spring.cloud.bootstrap.enabled=true
+spring.cloud.kubernetes.discovery.enabled=false
\ No newline at end of file
diff --git a/kogito-springboot/bom/pom.xml b/kogito-springboot/bom/pom.xml
index d4b241226cb..2e2ce45d02a 100644
--- a/kogito-springboot/bom/pom.xml
+++ b/kogito-springboot/bom/pom.xml
@@ -34,20 +34,24 @@
   <properties>
     <!-- Used to define which poms are allowed to have dependencyManagement 
sections. This is to enforce the convention that only the root pom should have 
dependencyManagement, and all other poms should inherit from it. -->
     <allowedPomsList>org.kie.kogito:kogito-spring-boot-bom</allowedPomsList>
-    <!-- Aligned with Spring Boot Cloud (spring-cloud-kubernetes-fabric8 5.0.1 
declares fabric8 7.4.0) -->
-    <version.io.fabric8>7.4.0</version.io.fabric8>
-    <version.io.netty>4.2.17.Final</version.io.netty>
+    <!-- Overrides kie-parent fabric8 7.3.1 to align with Spring Cloud.
+         spring-cloud-dependencies:${version.org.springframework.cloud} imports
+         spring-cloud-kubernetes-fabric8:5.0.2, which requires io.fabric8 
7.4.1.
+         When upgrading version.org.springframework.cloud, re-check the 
fabric8 version
+         declared by spring-cloud-kubernetes-fabric8 in the new 
spring-cloud-dependencies BOM. -->
+    <version.io.fabric8>7.4.1</version.io.fabric8>
+    <version.io.netty>4.2.18.Final</version.io.netty>
     <version.jakarta.servlet>6.0.0</version.jakarta.servlet>
     <version.org.springdoc>2.8.13</version.org.springdoc>
     <version.org.springframework>7.0.9</version.org.springframework>
-    <version.org.springframework.boot>4.0.8</version.org.springframework.boot>
-    
<version.org.springframework.cloud>2025.1.1</version.org.springframework.cloud>
-    <!-- CVE-2026-49844: Spring Boot 4.0.7 sets log4j2.version=2.25.4 which is 
vulnerable.
+    <version.org.springframework.boot>4.1.1</version.org.springframework.boot>
+    
<version.org.springframework.cloud>2025.1.2</version.org.springframework.cloud>
+    <!-- CVE-2026-49844: Spring Boot 4.1.1 sets log4j2.version=2.25.5 which is 
vulnerable.
          Override the version property inherited from kie-parent to 2.26.1 
(minimum 2.25.5).
          https://logging.apache.org/security.html#CVE-2026-49844 -->
     <version.org.apache.logging.log4j>2.26.1</version.org.apache.logging.log4j>
     <!-- CVE-2026-59889: force-pin jackson-databind to 3.1.6.
-         spring-boot-dependencies:4.0.8 carries the vulnerable 
jackson-databind:3.1.5.
+         spring-boot-dependencies:4.1.1 carries the vulnerable 
jackson-databind:3.1.5.
          Remove this pin once spring-boot-dependencies imports 
jackson-databind >= 3.1.6. -->
     <version.tools.jackson.core>3.1.6</version.tools.jackson.core>
     <!-- Framework-specific pins moved out of kie-parent: only this tree 
declares these artifacts. -->
@@ -85,8 +89,8 @@
         <type>pom</type>
         <scope>import</scope>
       </dependency>
-      <!-- CVE fix: spring-boot-dependencies:4.0.x imports 
mongodb-driver-bom:5.6.5 which pins
-           mongodb-driver-core and bson to 5.6.5. Override to match 
mongodb-driver-sync:5.9.2.
+      <!-- CVE fix: spring-boot-dependencies:4.1.1 imports 
mongodb-driver-bom:5.8.1 which pins
+           mongodb-driver-core and bson to 5.8.1. Override to match 
mongodb-driver-sync:5.9.2.
            https://jira.mongodb.org/browse/JAVA-6266 -->
       <dependency>
         <groupId>org.mongodb</groupId>
diff --git a/optaplanner-build/optaplanner-build-parent/pom.xml 
b/optaplanner-build/optaplanner-build-parent/pom.xml
index 06bce776361..48262397c66 100644
--- a/optaplanner-build/optaplanner-build-parent/pom.xml
+++ b/optaplanner-build/optaplanner-build-parent/pom.xml
@@ -65,7 +65,7 @@
     <!-- CVE-2026-56624: Apache MINA SSHD fixed version -->
     <version.org.apache.sshd>2.19.0</version.org.apache.sshd>
     <version.org.springframework>7.0.9</version.org.springframework>
-    <version.org.springframework.boot>4.0.8</version.org.springframework.boot>
+    <version.org.springframework.boot>4.1.1</version.org.springframework.boot>
     
<version.com.fasterxml.jackson.databind>2.22.2</version.com.fasterxml.jackson.databind>
     <!-- 
************************************************************************ -->
     <!-- Plugins -->


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to