Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESBROADCOMVERIFIED

PUBLISHER UPDATE · SPRING-BOOT-4.1.0-RC1

SPRING-BOOT-4.1.0-RC1 release notes and known issues

v4.1.0-RC1

Scope: Spring Boot. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

⭐ New Features Add support for docker.elastic.co/elasticsearch/elasticsearch #50119 Narrow the scope of icons pattern to /icons/icon-* #50084 Add configuration options for KafkaTemplate's allowNonTransactional and closeTimeout #49954 Align ReactorHttpClientBuilder defaults with Spring Framework and provide an opt-out #49950 Add support for providing a custom SessionTimeout bean #49883 Add support for Redis Annotation driven listeners #49858 Support spring.webflux.default-html-escape property for application-wide HTML escaping configuration #49791 Add fallback support for '/opt/homebrew/bin' on macOS #49721 Support InetAddress filtering for HTTP Clients #49687 Monitor certificates from truststore in SslMeterBinder #49641 Enable ansi support by default on Windows 11+ #49571 Add ' @GrpcAdvice ' exception handling support #49053 Add support for OpenTelemetry SDK environment variables #48799 Add ability to read custom layers.xml from classpath #32466 Support LazyConnectionDataSourceProxy #15480 🐞 Bug Fixes Default security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not #50190 Elasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client #50189 ApplicationPidFileWriter does not handle symlinks correctly #50186 RandomValuePropertySource is not suitable for secrets #50184 Cassandra auto-configuration misconfigures CqlSessionBuilder #50182 ApplicationTemp does not handle symlinks correctly #50179 Remote DevTools performs comparison incorrectly #50177 spring.rabbitmq.ssl.verify-hostname is applied inconsistently #50175 GrpcDisableCsrfHttpConfigurer incorrectly uses inverse of 'spring.grpc.server.security.csrf.enabled' property #50145 API versioning path strategy should be applied path last as it is not meant to yield #50127 Whole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter #50078 Classic starters are missing several modules #50072 Module spring-boot-resttestclient is missing from spring-boot-starter-test-classic #50070 Annotations like @Ssl don't work on @Bean methods when using @ServiceConnection #50065 EnversRevisionRepositoriesRegistrar should reuse @EnableEnversRepositories rather than configuring the JPA counterpart #50040 WebFlux Cloud Foundry links endpoint includes query string from received request in resolved links #50018 Imports on a containing test class are ignored when a nested class has imports #50013 Spring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test #49988 Reactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver #49958 With spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled #49957 500 response from env endpoint when supplied pattern is invalid #49947 HTTP method is lost when configuring excludes in EndpointRequest #49944 Honor HttpMethod for reactive additional endpoint paths #49881 Docker Compose support doesn't work with apache/artemis image #49870 Docker Compose support doesn't work with apache/activemq image #49867 ReactiveOAuth2ResourceServerAutoConfiguration should trigger only on real Reactive Applications #49807 Test starters 'spring-boot-starter-grpc-client-test' and 'spring-boot-starter-grpc-server-test' are missing #49690 Properties in ' @ConfigurationProperties ' annotated type shouldn't be able to define the same ' @Name ' #49565 Distribution's SLO, minimum expected value, and maximum expected value are not applied to long task timer meters #49190 WebConversionService breaks embedded value resolving #8923 📔 Documentation Update docs to encourage Java fundamentals for beginners that prefer to learn that way #50147 HTTP Service Interface Clients still document that API versioning can be configured via properties #50128 Link to the observability section of the Lettuce documentation is broken #50098 Javadoc for StaticResour

Improvements and security content

  • ⭐ New Features Add support for docker.elastic.co/elasticsearch/elasticsearch #50119 Narrow the scope of icons pattern to /icons/icon-* #50084 Add configuration options for KafkaTemplate's allowNonTransactional and closeTimeout #49954 Align ReactorHttpClientBuilder defaults with Spring Framework and provide an opt-out #49950 Add support for providing a custom SessionTimeout bean #49883 Add support for Redis Annotation driven listeners #49858 Support spring.webflux.default-html-escape property for application-wide HTML escaping configuration #49791 Add fallback support for '/opt/homebrew/bin' on macOS #49721 Support InetAddress filtering for HTTP Clients #49687 Monitor certificates from truststore in SslMeterBinder #49641 Enable ansi support by default on Windows 11+ #49571 Add ' @GrpcAdvice ' exception handling support #49053 Add support for OpenTelemetry SDK environment variables #48799 Add ability to read custom layers.xml from classpath #32466 Support LazyConnectionDataSourceProxy #15480 🐞 Bug Fixes Default security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not #50190 Elasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client #50189 ApplicationPidFileWriter does not handle symlinks correctly #50186 RandomValuePropertySource is not suitable for secrets #50184 Cassandra auto-configuration misconfigures CqlSessionBuilder #50182 ApplicationTemp does not handle symlinks correctly #50179 Remote DevTools performs comparison incorrectly #50177 spring.rabbitmq.ssl.verify-hostname is applied inconsistently #50175 GrpcDisableCsrfHttpConfigurer incorrectly uses inverse of 'spring.grpc.server.security.csrf.enabled' property #50145 API versioning path strategy should be applied path last as it is not meant to yield #50127 Whole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter #50078 Classic starters are missing several modules #50072 Module spring-boot-resttestclient is missing from spring-boot-starter-test-classic #50070 Annotations like @Ssl don't work on @Bean methods when using @ServiceConnection #50065 EnversRevisionRepositoriesRegistrar should reuse @EnableEnversRepositories rather than configuring the JPA counterpart #50040 WebFlux Cloud Foundry links endpoint includes query string from received request in resolved links #50018 Imports on a containing test class are ignored when a nested class has imports #50013 Spring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test #49988 Reactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver #49958 With spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled #49957 500 response from env endpoint when supplied pattern is invalid #49947 HTTP method is lost when configuring excludes in EndpointRequest #49944 Honor HttpMethod for reactive additional endpoint paths #49881 Docker Compose support doesn't work with apache/artemis image #49870 Docker Compose support doesn't work with apache/activemq image #49867 ReactiveOAuth2ResourceServerAutoConfiguration should trigger only on real Reactive Applications #49807 Test starters 'spring-boot-starter-grpc-client-test' and 'spring-boot-starter-grpc-server-test' are missing #49690 Properties in ' @ConfigurationProperties ' annotated type shouldn't be able to define the same ' @Name ' #49565 Distribution's SLO, minimum expected value, and maximum expected value are not applied to long task timer meters #49190 WebConversionService breaks embedded value resolving #8923 📔 Documentation Update docs to encourage Java fundamentals for beginners that prefer to learn that way #50147 HTTP Service Interface Clients still document that API versioning can be configured via properties #50128 Link to the observability section of the Lettuce documentation is broken #50098 Javadoc for StaticResour

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Spring Boot

Affected versions

  • 4.1.0-RC1

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence