1. 9063673 Update Spring Cloud Netfix to 5.0.2 by Andriy Redko · 17 hours ago main
  2. 767e761 Fix Mockito agent warnings (#3200) by Andriy Redko · 20 hours ago
  3. 62711a2 Bump com.sun.xml.messaging.saaj:saaj-impl from 3.0.5 to 3.0.6 (#3205) by dependabot[bot] · 26 hours ago
  4. 73ed77c Bump cxf.opentelemetry.version from 1.62.0 to 1.63.0 (#3206) by dependabot[bot] · 26 hours ago
  5. 9b1e6a9 Bump com.sun.xml.ws:jaxws-rt from 4.0.4 to 4.0.5 (#3204) by dependabot[bot] · 26 hours ago
  6. e613b1a Update Spring Boot to 4.0.7 by Andriy Redko · 35 hours ago
  7. b07f315e Update Spring Boot to 4.0.7 by Andriy Redko · 35 hours ago
  8. 67cd317 Bump org.apache.maven.plugins:maven-dependency-plugin (#3202) by dependabot[bot] · 2 days ago
  9. aff5675 Update Jackson Databind to 3.2.0 by Andriy Redko · 2 days ago
  10. 1eca2d0 Bump cxf.jackson.version from 3.1.4 to 3.2.0 (#3201) by dependabot[bot] · 2 days ago
  11. 3873d69 Bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15 (#3203) by dependabot[bot] · 2 days ago
  12. cc3ed0d Update Spring Security to 7.0.6 by Andriy Redko · 3 days ago
  13. 5d3acd4 Bump jakarta.json.bind:jakarta.json.bind-api from 3.0.1 to 3.0.2 (#3199) by dependabot[bot] · 3 days ago
  14. 9ebee58 Bump jaxen:jaxen from 2.0.4 to 2.0.5 (#3198) by dependabot[bot] · 3 days ago
  15. 4fd8325 Bump org.eclipse.parsson:parsson from 1.1.7 to 1.1.9 (#3196) by dependabot[bot] · 3 days ago
  16. 6af0e6f Update Spring LDAP to 4.0.4 by Andriy Redko · 4 days ago
  17. e3caea1 Update Micrometer to 1.16.6 by Andriy Redko · 4 days ago
  18. 26b3f2d Update Micrometer Tracing to 1.6.6 by Andriy Redko · 4 days ago
  19. 3510561 Update Project Reactor to 3.8.6 by Andriy Redko · 4 days ago
  20. d1abc0b Update Spring Framework to 7.0.8 by Andriy Redko · 4 days ago
  21. d2b4d54 Update JUnit Jupiter to 6.1.0 in cfx-tck by Andriy Redko · 4 days ago
  22. 315d762 Update Glassfish to 8.0.3 by Andriy Redko · 4 days ago
  23. 74f1dda Configure GitHub workflows to use concurrency cancel-in-progress for (#3195) by Aurélien Pupier · 4 days ago
  24. cdd8cb0 Add sensible default value to attachment-max-size property (#3188) by Andriy Redko · 4 days ago
  25. 5936885 Bump github/codeql-action from 4.36.0 to 4.36.1 (#3192) by dependabot[bot] · 4 days ago
  26. 3ac370e Bump org.jboss.ws.cxf:jbossws-cxf-client from 7.3.8.Final to 7.4.0.Final (#3190) by dependabot[bot] · 4 days ago
  27. 675f2fc7 Bump org.apache.mina:mina-core from 2.2.7 to 2.2.8 (#3191) by dependabot[bot] · 4 days ago
  28. 01c5494 Bump actions/checkout from 6.0.2 to 6.0.3 (#3193) by dependabot[bot] · 4 days ago
  29. c2ee4f9 Bump ch.qos.logback:logback-classic from 1.5.33 to 1.5.34 (#3194) by dependabot[bot] · 4 days ago
  30. 58d9bac Bump org.graalvm.buildtools:native-maven-plugin from 1.1.0 to 1.1.1 (#3189) by dependabot[bot] · 4 days ago
  31. c8eb3c4 Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.33 (#3183) by dependabot[bot] · 7 days ago
  32. 011c52d Removing deprecated junit ExpectedException.none (#3187) by Colm O hEigeartaigh · 7 days ago
  33. bcc0878 Bump org.jboss.ws:jbossws-api from 3.0.0.Final to 3.1.0.Final (#3185) by dependabot[bot] · 7 days ago
  34. f7aee7a Bump com.puppycrawl.tools:checkstyle from 13.4.2 to 13.5.0 (#3184) by dependabot[bot] · 7 days ago
  35. a80cf85 Bump net.sourceforge.pmd:pmd-core from 7.24.0 to 7.25.0 (#3186) by dependabot[bot] · 7 days ago
  36. 56936ea Update version in some pom.xml files by Andriy Redko · 7 days ago
  37. ca5c4a7 Fix JAXRS20ClientServerBookTest.testGetGenericBookManyClientsInParallel test case by Andriy Redko · 7 days ago
  38. 39bd0a3 [maven-release-plugin] prepare for next development iteration by Freeman Fang · 8 days ago
  39. d2b2776 [maven-release-plugin] prepare release cxf-4.2.2 by Freeman Fang · 8 days ago cxf-4.2.2
  40. 0eabd1f Update Jackson Annotations to 2.22 by Andriy Redko · 8 days ago
  41. afdc7f2 update CXF 4.2.2 release notes by Freeman Fang · 8 days ago
  42. 0cb59d7 Bump tools.jackson.core:jackson-databind from 3.1.3 to 3.1.4 (#3180) by dependabot[bot] · 8 days ago
  43. b219f08 Update jaxb-tools to 4.0.15 by Andriy Redko · 8 days ago
  44. 1a16a0a Introduce default value for maxFormParameterCount (#3177) by Andriy Redko · 8 days ago
  45. d43cd04 Bump org.glassfish.jaxb:jaxb-xjc from 4.0.8 to 4.0.9 (#3181) by dependabot[bot] · 8 days ago
  46. 5de63cb Bump org.webjars:swagger-ui from 5.32.5 to 5.32.6 (#3179) by dependabot[bot] · 8 days ago
  47. 747e09f Bump org.sonarsource.scanner.maven:sonar-maven-plugin (#3178) by dependabot[bot] · 8 days ago
  48. a4b17ea compare username token password and digest in constant time (#3182) by Javid Khan · 8 days ago
  49. f49e612 Bump cxf.dropwizard4.version from 4.2.38 to 4.2.39 (#3173) by dependabot[bot] · 9 days ago
  50. 7c2845e Bump cxf.hibernate.em.version from 7.3.6.Final to 7.4.0.Final (#3174) by dependabot[bot] · 9 days ago
  51. 3db372d Bump jaxen:jaxen from 2.0.3 to 2.0.4 (#3175) by dependabot[bot] · 9 days ago
  52. 1c8e962 Add umbrella threat model + AGENTS.md and link from SECURITY.md for security-model discoverability (#3158) by Jarek Potiuk · 9 days ago
  53. 2d0e615 Update Jetty to 12.1.10 (#3082) by Andriy Redko · 9 days ago
  54. 8574198 compare pkce code verifier and client secret hash in constant time (#3170) by Javid Khan · 9 days ago
  55. 2b8e8b1 Add default constraints on the number of JSON objects/array entries that can be parsed (#3172) by Colm O hEigeartaigh · 9 days ago
  56. fd8674c escape raw quotes after an escaped backslash in escapeJson (#3167) by Javid Khan · 9 days ago
  57. 37b2d81 [CXF-9213]make RetryStrategy stateless (#3143) by Freeman(Yue) Fang · 10 days ago
  58. 59d04c3 Fix org.apache.cxf.systest.http2.netty.NettyClientServerHttp2Test test cases (due to Netty changes) by Andriy Redko · 10 days ago
  59. 0c07da7 Update Netty 4.2.15.Final by Andriy Redko · 10 days ago
  60. cc0ef24 Add limit to the maximum number of attachment headers to be collected (#3159) by Andriy Redko · 10 days ago
  61. 7cfa2fb More SchemaFactory hardenings (#3157) by Andriy Redko · 10 days ago
  62. f8b09f7 Get the headers from the validated signature entry (#3171) by Colm O hEigeartaigh · 10 days ago
  63. 2dff320 Properly handle nested arrays in json parsing (#3168) by Colm O hEigeartaigh · 10 days ago
  64. 1897887 Harden JNDI for integration/jca (#3169) by Colm O hEigeartaigh · 10 days ago
  65. 5e96ddb compare oauth2 secret tokens with constant-time MessageDigest.isEqual (#3165) by Javid Khan · 10 days ago
  66. 2013d00 Bump org.apache.maven.plugins:maven-surefire-report-plugin (#3163) by dependabot[bot] · 11 days ago
  67. 7de9141 Bump cxf.dropwizard5.version from 5.0.6 to 5.0.7 (#3162) by dependabot[bot] · 11 days ago
  68. 01828d6 Bump github/codeql-action from 4.35.5 to 4.36.0 (#3161) by dependabot[bot] · 11 days ago
  69. c5193b0 Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.5 to 3.5.6 (#3160) by dependabot[bot] · 11 days ago
  70. 2e1fd49 [CXF-9218]Respect configured ProxySelector instead of hard-wiring system proxy properties (#3154) by Freeman(Yue) Fang · 14 days ago
  71. 2e26e6c [CXF-9129]Chunked attachment streaming not working when using ws-security (#3153) by Freeman(Yue) Fang · 14 days ago
  72. 89de93d Bump org.ow2.asm:asm from 9.10 to 9.10.1 (#3156) by dependabot[bot] · 2 weeks ago
  73. 1074a25 Bump cxf.hibernate.em.version from 7.3.5.Final to 7.3.6.Final (#3155) by dependabot[bot] · 2 weeks ago
  74. 51b7f0d Apply the JSON depth limit to writes as well (#3152) by Colm O hEigeartaigh · 2 weeks ago
  75. 2d8f9c5 [CXF-8966] : fix validation of nil int in xsd (#3151) by Andriy Redko · 2 weeks ago
  76. 50a92ec Add a depth limit for JSON parsing mirroring what Jettison does (#3149) by Colm O hEigeartaigh · 2 weeks ago
  77. b6941a3 More JNDI validation (#3150) by Colm O hEigeartaigh · 2 weeks ago
  78. 57c7d76 UriInfoImpl import proper StringUtils (#3148) by Markus Jung · 2 weeks ago
  79. a9dc98b Bump cxf.tika.version from 3.3.0 to 3.3.1 (#3146) by dependabot[bot] · 2 weeks ago
  80. 1986c0b Escape JSON control characters (#3145) by Colm O hEigeartaigh · 2 weeks ago
  81. 38d4ed1 Bump org.apache.maven.plugins:maven-site-plugin from 3.21.0 to 3.22.0 (#3144) by dependabot[bot] · 2 weeks ago
  82. 4197b3f Support unicode characters in the json parser (#3142) by Colm O hEigeartaigh · 2 weeks ago
  83. bc86f63 Improve JSON key parsing (#3141) by Colm O hEigeartaigh · 3 weeks ago
  84. beff5cc Fix bug in JSON parsing relating to escaped backslashes (#3140) by Colm O hEigeartaigh · 3 weeks ago
  85. acf9d58 Bump github/codeql-action from 4.35.4 to 4.35.5 (#3139) by dependabot[bot] · 3 weeks ago
  86. 942a663 Handle NaN or infinite times in JSON/JWT (#3137) by Colm O hEigeartaigh · 3 weeks ago
  87. 46851d9 Update Woodstox to 7.2.0 (#3138) by Andriy Redko · 3 weeks ago
  88. 6559419 Update JUnit Jupiter to 6.1.0 by Andriy Redko · 3 weeks ago
  89. 9fc78f6 Removing control characters from OAuth2 realm and logs (#3136) by Colm O hEigeartaigh · 3 weeks ago
  90. 5821d3e Bump cxf.hibernate.em.version from 7.3.4.Final to 7.3.5.Final (#3135) by dependabot[bot] · 3 weeks ago
  91. 013cf51 Synchronize access token refresh when refresh tokens aren't recycled (#3133) by Colm O hEigeartaigh · 3 weeks ago
  92. 9bfdf70 Remove TLS v1 + 1.1 from the default protocol list (#3134) by Colm O hEigeartaigh · 3 weeks ago
  93. bb22563 CXF-9216 - Switch default OAuth2 code verifier to Digest (#3132) by Colm O hEigeartaigh · 3 weeks ago
  94. 2ac45fd Bump jaxen:jaxen from 2.0.2 to 2.0.3 (#3130) by dependabot[bot] · 3 weeks ago
  95. 5fbaf3f Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.6.2 to 3.6.3 (#3129) by dependabot[bot] · 3 weeks ago
  96. 62001e8 Removing OAuthServiceExceptionMapper which isn't used anywhere (#3128) by Colm O hEigeartaigh · 3 weeks ago
  97. 02b8e46 Fix the OAuth2 client ip address check and add a test (#3127) by Colm O hEigeartaigh · 3 weeks ago
  98. 68aa7c4 Update Glassfish to 8.0.2 by Andriy Redko · 3 weeks ago
  99. 6908418 Update Arquillian to 1.10.2.Final by Andriy Redko · 3 weeks ago
  100. 68c7bef Update Undertow to 2.4.1.Final by Andriy Redko · 3 weeks ago