417511458 / jbone

jbone基于Spring Cloud框架开发,旨在为中小企业提供稳定的微服务解决方案,为开发人员提供基础开发骨架,jbone包含微服务中所有常用组件,例如注册中心、服务管理、服务监控、JVM监控、内存分析、调用链跟踪、API网关等等。业务功能包括系统权限的统一管理、单点登录、CMS、电商平台、工作流平台、支付平台等等。
http://jbone.cn/
Apache License 2.0
999 stars 514 forks source link

Bump org.apache.shiro:shiro-core from 1.4.0 to 1.13.0 in /jbone-common #47

Open dependabot[bot] opened 10 months ago

dependabot[bot] commented 10 months ago

Bumps org.apache.shiro:shiro-core from 1.4.0 to 1.13.0.

Release notes

Sourced from org.apache.shiro:shiro-core's releases.

Apache Shiro 1.13.0

What's Changed

Full Changelog: https://github.com/apache/shiro/compare/shiro-root-1.12.0...shiro-root-1.13.0

shiro-root-1.12.0

What's Changed

... (truncated)

Changelog

Sourced from org.apache.shiro:shiro-core's changelog.

Licensed to the Apache Software Foundation (ASF) under one

or more contributor license agreements. See the NOTICE file

distributed with this work for additional information

regarding copyright ownership. The ASF licenses this file

to you under the Apache License, Version 2.0 (the

"License"); you may not use this file except in compliance

with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing,

software distributed under the License is distributed on an

"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY

KIND, either express or implied. See the License for the

specific language governing permissions and limitations

under the License.

This is not an official release notes document. It exists for Shiro developers to jot down their notes while working in the source code. These notes will be combined with Jira’s auto-generated release notes during a release for the total set.

###########################################################

2.0.0

###########################################################

Improvement

[SHIRO-290] Implement bcrypt and argon2 KDF algorithms

Backwards Incompatible Changes

  • Changed default DefaultPasswordService.java algorithm to "Argon2id".
  • PasswordService.encryptPassword(Object plaintext) will now throw a NullPointerException on null parameter. It was never specified how this method would behave.
  • Made salt non-nullable.
  • Removed methods in PasswordMatcher.

###########################################################

1.7.1

###########################################################

Bug

[SHIRO-797] - Shiro 1.7.0 is lower than using springboot version 2.0.7 dependency error

###########################################################

... (truncated)

Commits
  • 8681958 [maven-release-plugin] prepare release shiro-root-1.13.0
  • f4daf3a Merge pull request #1148 from apache/dependabot/maven/1.13.x/com.ibm.icu-icu4...
  • 02e1f66 build(deps): bump com.ibm.icu:icu4j from 73.2 to 74.1
  • d62387d Add tests for SavedRequest redirects
  • 3b80f5c The InvalidRequestFilter is more flexible
  • 443135b Revert "[maven-release-plugin] prepare release shiro-root-1.13.0"
  • 208e0b8 Revert "[maven-release-plugin] prepare for next development iteration"
  • e4c217c [maven-release-plugin] prepare for next development iteration
  • fb46976 [maven-release-plugin] prepare release shiro-root-1.13.0
  • 4e71c79 Merge pull request #1144 from fpapon/SHIRO-1143
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/417511458/jbone/network/alerts).