codeconsole opened a new pull request, #16408:
URL: https://github.com/apache/grails-core/pull/16408

   Moves 9.0.x from Spring Boot 4.1.1 to Spring Boot 4.2. It currently targets 
**4.2.0-M2** and will be bumped through the remaining milestones and release 
candidates until 4.2.0 is released.
   
   ### Managed versions that change
   
   | | Spring Boot 4.1.1 | Spring Boot 4.2.0-M2 |
   |---|---|---|
   | Spring Framework | 7.0.9 | 7.1.0-M2 |
   | Spring Security | 7.1.1 | 7.2.0-M2 |
   | Spring Data | 2026.0.1 | 2026.1.0-M2 |
   | Micrometer | 1.17.1 | 1.18.0-M2 |
   | Reactor | 2025.0.7 | 2026.0.0-M2 |
   | JUnit Jupiter | 6.0.3 | 6.1.3 |
   | Tomcat | 11.0.24 | 11.0.26 |
   | graphql-java | 25.0 | 26.1 |
   | Jedis | 7.4.1 | 8.0.1 |
   | H2 | 2.4.240 | 2.5.250 |
   
   ### Changes Spring Boot 4.2 requires
   
   - **Spring Framework 7.1 renamed `ClassNameGenerator` to `NameGenerator`** 
(same constructors). Only the AOT specs in `grails-core` used it.
   - **`BeanFactory.getBean(String, ParameterizedTypeReference)` is a new 
abstract method.** `MockApplicationContext` implements it with the same name 
and type checks as `getBean(String, Class)`.
   - **graphql-java 26 only accepts `GraphQLNamedType` in 
`GraphQLSchema.Builder.additionalTypes`.** 
`GraphQLSchemaInterceptor.interceptSchema` keeps its `Set<GraphQLType>` 
parameter, so existing interceptors still override it. `Schema` unwraps list 
and non-null wrappers before building the schema, which adds the same named 
type graphql-java 25 reached by traversing the wrapper:
   
     ```groovy
     void interceptSchema(GraphQLObjectType.Builder queryType,
                          GraphQLObjectType.Builder mutationType,
                          Set<GraphQLType> additionalTypes) {
         additionalTypes << 
GraphQLNonNull.nonNull(GraphQLList.list(reportType)) // adds ReportType
     }
     ```
   
     `grails-bom` now manages graphql-java 26.1. graphql-java-extended-scalars 
has no release newer than 24.0; the `grails-data-graphql` core and plugin tests 
pass with 24.0 on graphql-java 26.1.
   - **Jedis 8 depends on `org.json:json:20260719`.** The SBOM license override 
approved in LEGAL-666 is keyed by version and moves with it.
   
   ### grails-bom
   
   - Jackson 3 (3.1.6), Logback (1.6.3) and Commons Codec (1.22.1) are no 
longer pinned: Spring Boot 4.2 manages those versions itself.
   - Jackson 2 stays on 2.22.2 because Groovy YAML needs 2.22.x (Spring Boot 
4.2 manages 2.21.6, which already has the CVE-2026-68497 and CVE-2026-19032 
fixes).
   - The MongoDB driver stays on 5.12.0. Spring Boot 4.2 manages 5.11.1, which 
already has the CVE-2026-18710 fix; the pin only avoids downgrading the driver.
   - The version-pinned vulnerability-scan exclusions for H2 and 
`spring-security-web` move to the versions Spring Boot 4.2.0-M2 manages.
   
   ### Documentation
   
   What's New now describes Spring Boot 4.2 and Spring Framework 7.1 and links 
their release notes.
   
   ### Limitations
   
   - Until 4.2.0 is released, 9.0.x snapshots depend on milestone releases of 
Spring Boot, Spring Framework, Spring Security, Spring Data, Micrometer and 
Reactor.
   - Each milestone bump has to move the version-pinned vulnerability-scan 
exclusions (`spring-security-web`, `h2`) and the `org.json` SBOM mapping if 
Spring Boot changes those versions, and re-check whether the MongoDB driver pin 
is still ahead of Spring Boot's.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to