struts-examples
struts-examples copied to clipboard
Bump struts2.version from 6.3.0.2 to 6.4.0
Bumps struts2.version from 6.3.0.2 to 6.4.0.
Updates org.apache.struts:struts2-core from 6.3.0.2 to 6.4.0
Release notes
Sourced from org.apache.struts:struts2-core's releases.
Struts 6.4.0
What's Changed
- WW-5341 Ensure exclusion list applies to objects from all ClassLoaders by
@kusalkin apache/struts#741- WW-5342 Add option to block use of default package by
@kusalkin apache/struts#742- WW-5339 Misc clean up in CompoundRootAccessor and OgnlValueStackTest by
@kusalkin apache/struts#745- WW-5340 Preliminary refactor of OgnlUtil by
@kusalkin apache/struts#746- [WW-5346] replace BeanManager::createInjectionTarget by
@heppthoin apache/struts#754- WW-5340 Introducing OGNL Guard by
@kusalkin apache/struts#747- WW-5348 Allow overriding of logging behaviour in DefaultAcceptedPatternsChecker by
@kusalkin apache/struts#757- [WW-5338] Removes deprecated OgnlTool by
@lukaszlenartin apache/struts#758- [WW-5344] Un-deprecates Sitemesh plugin and upgrades Sitmesh to ver 2.5.0 by
@lukaszlenartin apache/struts#759- WW-5340 Mild refactor StrutsOgnlGuard for easier subclassing by
@kusalkin apache/struts#760- WW-5349 Remove Struts core dependency on OGNL VarRefs by
@kusalkin apache/struts#763- WW-5354 Ensure ActionSupport fields are not parameter injectable by
@kusalkin apache/struts#765- WW-5355 Integrate W-TinyLfu cache and use by default by
@kusalkin apache/struts#766- Improved the StrutsUrlDecoder so that charset retrieval is performed only once. by
@mygreenin apache/struts#773- WW-5358 Expand exclusion lists by
@kusalkin apache/struts#774- WW-5350 Refactor SecurityMemberAccess by
@kusalkin apache/struts#780- [WW-5333] Refactors AttributeMap by
@lukaszlenartin apache/struts#779- WW-5363 Velocity: read chained contexts before ValueStack by
@kusalkin apache/struts#789- WW-5350 Implement OGNL Allowlist capability by
@kusalkin apache/struts#781- WW-5363 Remove redundant method from VelocityManager by
@kusalkin apache/struts#793- WW-5343 Make SecurityMemberAccess an extensible bean by
@kusalkin apache/struts#791- WW-5364 Automatically populate OGNL allowlist by
@kusalkin apache/struts#800- WW-5339 Add option to block custom OGNL maps by
@kusalkin apache/struts#806- [WW-5370] Makes HttpParameters case-insensitive by
@lukaszlenartin apache/struts#807- [WW-5371] Modern upload by
@lukaszlenartin apache/struts#808- WW-5364 Add missing system allowlist classes by
@kusalkin apache/struts#815- [WW-5373] Update JavaDoc CspReportAction.java by
@assachsin apache/struts#814- [WW-5328] Removes deprecated setters by
@lukaszlenartin apache/struts#811- [WW-5362] Removes type attribute out of tag by
@lukaszlenartin apache/struts#812- WW-5378 Add option to NOT fallback to context lookup when finding value on OgnlValueStack by
@kusalkin apache/struts#821- WW-5364 Add String.class to system allowlist by
@kusalkin apache/struts#828- WW-5381 Introduce RootAccessor interface for extension point by
@kusalkin apache/struts#823- WW-5379 Implement alternative mechanism for Velocity directives to obtain ValueStack by
@kusalkin apache/struts#822- WW-5352 Repackage ParametersInterceptor and related classes by
@kusalkin apache/struts#829- WW-5381 Introduce extension point for CompoundRootAccessor by
@kusalkin apache/struts#824- [WW-5383] Updates RegEx to excludes JARs by default by
@lukaszlenartin apache/struts#830- WW-5382 Fix stale injections in Dispatcher by
@kusalkin apache/struts#826- WW-5381 Introduce extension point for MethodAccessor by
@kusalkin apache/struts#825- WW-5352 Refactor ParametersInterceptor by
@kusalkin apache/struts#831- [WW-5365] Reverts changes introduced in WW-5192 to allow evaluate the value attribute of Radio tag by
@lukaszlenartin apache/struts#835- WW-5352 Clean up OgnlValueStackTest by
@kusalkin apache/struts#841- [WW-5387] Fixes remove() signature by
@lukaszlenartin apache/struts#844- [WW-5369] Re-define minimal library set by
@lukaszlenartin apache/struts#847- [WW-5374] Allows to prepend reportUri with Servlet context by
@lukaszlenartin apache/struts#845- [WW-5357] Adds support for disabled attribute to anchor tag by
@lukaszlenartin apache/struts#848- WW-5352 Introducing the StrutsParameter annotation by
@kusalkin apache/struts#832- [WW-5360] Introduces additional countStr & indexStr to allow to ignore conversion by
@lukaszlenartin apache/struts#852- WW-5391 Add interface for VelocityManager extension point by
@kusalkin apache/struts#867
... (truncated)
Commits
- See full diff in compare view
Updates org.apache.struts:struts2-config-browser-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-convention-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-bean-validation-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-junit-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-jfreechart-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-json-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-spring-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-portlet-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-dwr-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-portlet-tiles-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-rest-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-tiles-plugin from 6.3.0.2 to 6.4.0
Updates org.apache.struts:struts2-jasperreports-plugin from 6.3.0.2 to 6.4.0
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)