Sign in
◑
Theme
apache
/
cxf
/
HEAD
f776b0d
Bump cxf.hibernate.em.version from 7.4.6.Final to 7.4.7.Final (#3455)
by dependabot[bot]
· 7 hours ago
main
4e77560
Bump org.apache.maven.plugins:maven-compiler-plugin (#3456)
by dependabot[bot]
· 7 hours ago
223fd2f
Fix secret key sizing for Spnego as well (#3454)
by Colm O hEigeartaigh
· 11 hours ago
b7d1fb9
Update Jetty to 12.1.13
by Andriy Redko
· 29 hours ago
bc5154d
Update Dropwizard Metrics to 4.2.40
by Andriy Redko
· 30 hours ago
d34ae62
Fix STS secret-key sizing (#3453)
by Colm O hEigeartaigh
· 30 hours ago
3fd6143
Add formParamsMaxSize to FormEncodingProvider and estimate form params count before decoding / parsing (#3444)
by Andriy Redko
· 31 hours ago
bb0766d
Bump cxf.dropwizard5.version from 5.0.7 to 5.0.8 (#3449)
by dependabot[bot]
· 31 hours ago
b5f9095
Bump jakarta.json.bind:jakarta.json.bind-api from 3.0.2 to 3.0.3 (#3450)
by dependabot[bot]
· 31 hours ago
a958b4b
Fixup #3423 Use a properly random source to generate digest client (#3451)
by Peter Palaga
· 32 hours ago
6d2b423
Harden Content-Disposition filename parsing against ReDoS (#3448)
by Colm O hEigeartaigh
· 2 days ago
913f72c
Put a max length on the Fiql search term and fix performance parsing issue (#3443)
by Colm O hEigeartaigh
· 2 days ago
ec3389a
Bump io.swagger.core.v3:swagger-jaxrs2-jakarta from 2.2.54 to 2.2.55 (#3445)
by dependabot[bot]
· 2 days ago
744d59d
Bump com.fasterxml.woodstox:woodstox-core from 7.2.1 to 7.2.2 (#3446)
by dependabot[bot]
· 2 days ago
8c2302b
Put a configurable limit on deeply parenthesized sub-expressions in the FiqlParser (#3442)
by Colm O hEigeartaigh
· 5 days ago
a814dac
Bump org.apache.felix:maven-bundle-plugin from 6.1.0 to 6.1.2 (#3440)
by dependabot[bot]
· 5 days ago
4656df1
Bump org.jboss.ws.cxf:jbossws-cxf-client from 7.4.0.Final to 7.4.1.Final (#3439)
by dependabot[bot]
· 5 days ago
cc6b208
Bump org.graalvm.buildtools:native-maven-plugin from 1.1.10 to 1.1.11 (#3437)
by dependabot[bot]
· 6 days ago
89579d9
Bump io.undertow:undertow-core from 2.4.2.Final to 2.4.3.Final (#3436)
by dependabot[bot]
· 6 days ago
7468e3c
Add a fallback to prevent attacks on RSA 1.5 in the Jose code (#3435)
by Colm O hEigeartaigh
· 6 days ago
177afac
Restrict default SAML encryption algorithms (#3434)
by Colm O hEigeartaigh
· 6 days ago
93075df
Make sure attachment-max-headers-count property is respected for repeated headers (#3430)
by Andriy Redko
· 7 days ago
266e0ca
Bump tools.jackson.core:jackson-databind from 3.2.1 to 3.2.2 (#3433)
by dependabot[bot]
· 7 days ago
0588b5f
Bump org.eclipse:yasson from 3.0.4 to 3.0.5 (#3432)
by dependabot[bot]
· 7 days ago
6a8067b
Bump org.apache.groovy:groovy from 5.0.8 to 5.1.1 (#3431)
by dependabot[bot]
· 7 days ago
6ccfc08
Make Netty client TLS code use hostname verification (#3429)
by Colm O hEigeartaigh
· 7 days ago
1f74aa7
Make sure attachment-max-header-size property is respected for repeated and multi-line headers (#3425)
by Andriy Redko
· 8 days ago
17185d8
Bump org.jruby:jruby from 10.1.0.0 to 10.1.1.0 (#3428)
by dependabot[bot]
· 8 days ago
7c9e098
Bump io.undertow.ee:undertow-servlet from 2.0.1.Final to 2.0.2.Final (#3427)
by dependabot[bot]
· 8 days ago
903c826
Bump commons-codec:commons-codec from 1.22.0 to 1.22.1 (#3426)
by dependabot[bot]
· 8 days ago
639cb57
Require in OidcRpAuthenticationFilter that IdTokens have an expiry (#3424)
by Colm O hEigeartaigh
· 8 days ago
b019644
Use a properly random source to generate digest client nonces (#3423)
by Colm O hEigeartaigh
· 8 days ago
6298bc5
Add default expiry for JwtAuthenticationClientFilter (#3422)
by Colm O hEigeartaigh
· 9 days ago
4d8c9f4
Enforce a default TTL in AbstractJwtAuthenticationFilter so that tokens that don't have exp will be checked for expiration by default (#3421)
by Colm O hEigeartaigh
· 9 days ago
4c765ba
Wire through the TLS server parameter for Netty (#3420)
by Colm O hEigeartaigh
· 9 days ago
dfc0272
Bump cxf.tika.version from 3.3.2 to 4.0.0 (#3409)
by dependabot[bot]
· 9 days ago
ff15bc0
Bump github/codeql-action/init from 4.37.7 to 4.37.9 (#3415)
by dependabot[bot]
· 9 days ago
92e33ee
Use properly random IDs for WS-N (#3412)
by Colm O hEigeartaigh
· 9 days ago
dc95f9a
Bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.9 (#3419)
by dependabot[bot]
· 9 days ago
092d2cc
Bump org.webjars:swagger-ui from 5.32.11 to 5.32.14 (#3417)
by dependabot[bot]
· 9 days ago
3534ed7
Bump actions/setup-java from 5.7.0 to 6.0.0 (#3416)
by dependabot[bot]
· 9 days ago
07a092a
Bump cxf.hibernate.em.version from 7.4.5.Final to 7.4.6.Final (#3413)
by dependabot[bot]
· 9 days ago
1e9d093
Don't skip hostname verification with a custom trust manager (#3411)
by Colm O hEigeartaigh
· 9 days ago
db8b889
Update Swagger Core to 2.2.54
by Andriy Redko
· 12 days ago
e7a54da
Bump cxf.activemq.artemis.version from 2.55.0 to 2.56.0 (#3407)
by dependabot[bot]
· 12 days ago
a837332
Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.3 (#3406)
by dependabot[bot]
· 12 days ago
4a9116d
Default Oauth2 encryption providers to use AES-GCM (#3408)
by Colm O hEigeartaigh
· 12 days ago
bc543bb
Use TikaInputStream to facilitate 4.0 migration
by Andriy Redko
· 12 days ago
3123c1a
Use a free port not 8080 for SeBootstrapTest (#3405)
by Colm O hEigeartaigh
· 12 days ago
a83656f
Fix bug in JwsInputStream and add tests (#3404)
by Colm O hEigeartaigh
· 13 days ago
a948b1f
Bump org.graalvm.buildtools:native-maven-plugin from 1.1.5 to 1.1.10 (#3403)
by dependabot[bot]
· 13 days ago
6819407
Bump org.cyclonedx:cyclonedx-maven-plugin from 2.9.2 to 2.9.3 (#3402)
by dependabot[bot]
· 13 days ago
333ed07
Set bufferPayload to false (#3401)
by Colm O hEigeartaigh
· 13 days ago
0124c91
Bump org.jspecify:jspecify from 1.0.0 to 1.0.1 (#3400)
by dependabot[bot]
· 2 weeks ago
0765cb5
Bump cxf.reactor.version from 3.8.6 to 3.8.7 (#3399)
by dependabot[bot]
· 2 weeks ago
4861d69
For OIDC, allow only relative URLs or absolute URLs with the same scheme and authority as the current RP (#3398)
by Colm O hEigeartaigh
· 2 weeks ago
041010c
Bump com.puppycrawl.tools:checkstyle from 13.8.0 to 14.0.0 (#3396)
by dependabot[bot]
· 2 weeks ago
42e0314
Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0 (#3397)
by dependabot[bot]
· 2 weeks ago
3c900aa
Fix deflate bomb in compression utils (#3394)
by Colm O hEigeartaigh
· 2 weeks ago
650bbf9
CXF-9233: AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT is not logged (#3372)
by Andriy Redko
· 2 weeks ago
ada0da5
Bump cxf.openfeign.version from 13.13 to 13.14 (#3395)
by dependabot[bot]
· 2 weeks ago
f304f2d
Bump net.sourceforge.pmd:pmd-java from 7.25.0 to 7.26.0 (#3303)
by dependabot[bot]
· 2 weeks ago
bb810a0
Bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 (#3388)
by dependabot[bot]
· 2 weeks ago
b71c3d9
Bump github/codeql-action/init from 4.37.6 to 4.37.7 (#3392)
by dependabot[bot]
· 2 weeks ago
2acffdd
Bump cxf.lucene.version from 10.5.0 to 10.5.1 (#3389)
by dependabot[bot]
· 2 weeks ago
57d9f63
[CXF-9241] - Remove ImplicitConfidentialGrantService (#3386)
by Colm O hEigeartaigh
· 2 weeks ago
94d69c2
Validate token hashes if they are available (#3385)
by Colm O hEigeartaigh
· 2 weeks ago
ef784fb
Bump cxf.opentelemetry.version from 1.64.0 to 1.65.0 (#3379)
by dependabot[bot]
· 3 weeks ago
dc39c26
Bump cxf.jackson.version from 3.2.1 to 3.2.2 (#3384)
by dependabot[bot]
· 3 weeks ago
2a130bc
Update Spring Security to 7.1.1
by Andriy Redko
· 3 weeks ago
c3c5d2e
Update Spring LDAP to 4.1.1
by Andriy Redko
· 3 weeks ago
8097db1
Introduce a TTL in the AbstractAccessTokenValidator cache (#3382)
by Colm O hEigeartaigh
· 3 weeks ago
4e051b2
Update Micrometer Tracing to 1.7.1
by Andriy Redko
· 3 weeks ago
c4a1d16
Update Micrometer to 1.17.1
by Andriy Redko
· 3 weeks ago
95df3ee
Update Spring Framework to 7.0.9
by Andriy Redko
· 3 weeks ago
706713d
Update Spring Boot to 4.1.1
by Andriy Redko
· 3 weeks ago
c6c9b73
Bump org.apache.camel.springboot:camel-spring-boot-dependencies (#3381)
by dependabot[bot]
· 3 weeks ago
694e05f
Bump cxf.tomcat.version from 11.0.24 to 11.0.25 (#3380)
by dependabot[bot]
· 3 weeks ago
4797b9ab
Bump org.hibernate.validator:hibernate-validator (#3378)
by dependabot[bot]
· 3 weeks ago
4fdf9fe
fix Invocation.Builder.property() not visible to HTTP transport (#3375)
by Neena P Jacob
· 3 weeks ago
2a90ce2
Bump org.apache.commons:commons-jexl3 from 3.6.4 to 3.7.0 (#3292)
by dependabot[bot]
· 3 weeks ago
e7b86b9
Bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1 (#3376)
by dependabot[bot]
· 3 weeks ago
a588b3f
Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.2 to 5.6.4 in /parent (#3371)
by dependabot[bot]
· 3 weeks ago
cefe44b
Bump cxf.johnzon.version from 2.1.0 to 2.2.0 (#3374)
by dependabot[bot]
· 4 weeks ago
d8f201b
Bump org.webjars:swagger-ui from 5.32.8 to 5.32.11 (#3368)
by dependabot[bot]
· 4 weeks ago
58fe3d1
CXF-9240 - OAuthJSONProvider.appendJsonPair() does not escape JSON string values (#3367)
by Colm O hEigeartaigh
· 4 weeks ago
a272d6c
Fix SHA comments
by Colm O hEigeartaigh
· 4 weeks ago
6f3e9de
Bump org.apache.groovy:groovy from 5.0.7 to 5.0.8 (#3365)
by dependabot[bot]
· 4 weeks ago
c21d5d3
Porting locking fixes to revokeRefreshToken (#3364)
by Colm O hEigeartaigh
· 4 weeks ago
6a24c19
Bump versions in coverage-report and cxf-rest-tck
by Andriy Redko
· 4 weeks ago
78910f8
Bump cxf.openwebbeans.version from 4.1.0 to 4.1.1 (#3363)
by dependabot[bot]
· 4 weeks ago
90206a2
Fix some atomicity issues in removeCodeGrant (#3358)
by Colm O hEigeartaigh
· 4 weeks ago
4d814b8
Revert "Update OpenTelemetry to 1.65.0"
by Andriy Redko
· 4 weeks ago
29d3443
Update OpenTelemetry to 1.65.0
by Andriy Redko
· 4 weeks ago
854c678
Update JUnit Jupiter to 6.1.3
by Andriy Redko
· 4 weeks ago
32007a0
Update AsyncHttpClient to 3.0.13
by Andriy Redko
· 4 weeks ago
d1a09b3
Update cxf-build-utils to 4.1.5-SNAPSHOT
by Andriy Redko
· 4 weeks ago
3ac37bc
Fixup action comments using pinact
by Colm O hEigeartaigh
· 4 weeks ago
0bf19d9
Bump github/codeql-action/init from 4.37.3 to 4.37.6 (#3362)
by dependabot[bot]
· 4 weeks ago
2cacc27
Bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.6 (#3360)
by dependabot[bot]
· 4 weeks ago
Next »