<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="atom.xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://jeap-admin-ch.github.io/blog</id>
    <title>jEAP Blog</title>
    <updated>2026-08-25T00:00:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://jeap-admin-ch.github.io/blog"/>
    <subtitle>jEAP Blog</subtitle>
    <icon>https://jeap-admin-ch.github.io/img/favicon.ico</icon>
    <entry>
        <title type="html"><![CDATA[jeap-spring-boot-parent - Release 40.2.0]]></title>
        <id>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.2.0</id>
        <link href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.2.0"/>
        <updated>2026-08-25T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[New version 40.2.0 of jeap-spring-boot-parent is available.]]></summary>
        <content type="html"><![CDATA[<p>New version <a href="https://github.com/jeap-admin-ch/jeap-spring-boot-parent/blob/v40.2.0/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class=""><code>40.2.0</code></a> of <code>jeap-spring-boot-parent</code> is available.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="changed">Changed<a href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.2.0#changed" class="hash-link" aria-label="Direct link to Changed" title="Direct link to Changed" translate="no">​</a></h3>
<ul>
<li class="">update jeap-opensearch-client-starter from 2.19.0 to 2.20.0</li>
<li class="">Exclude the optional Jackson 2 core and databind dependencies from the OpenSearch Java client.</li>
</ul>]]></content>
        <author>
            <name>jEAP Team</name>
            <uri>https://github.com/jeap-admin-ch</uri>
        </author>
        <category label="Release" term="Release"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[jeap-spring-boot-parent - Release 40.1.0]]></title>
        <id>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.1.0</id>
        <link href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.1.0"/>
        <updated>2026-08-24T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[New version 40.1.0 of jeap-spring-boot-parent is available.]]></summary>
        <content type="html"><![CDATA[<p>New version <a href="https://github.com/jeap-admin-ch/jeap-spring-boot-parent/blob/v40.1.0/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class=""><code>40.1.0</code></a> of <code>jeap-spring-boot-parent</code> is available.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="changed">Changed<a href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.1.0#changed" class="hash-link" aria-label="Direct link to Changed" title="Direct link to Changed" translate="no">​</a></h3>
<ul>
<li class="">Update parent from 9.0.0 to 9.0.1</li>
<li class="">update jeap-spring-boot-tls-starter from 19.27.0 to 19.28.0</li>
<li class="">update jeap-opensearch-index-type from 1.24.0 to 1.25.0</li>
<li class="">update jeap-db-schema-publisher from 3.28.0 to 3.29.0</li>
<li class="">update jeap-spring-boot-roles-anywhere-starter from 3.29.0 to 3.30.0</li>
<li class="">update jeap-spring-boot-db-migration-starter from 19.27.0 to 19.28.0</li>
<li class="">update jeap-spring-boot-config-aws-starter from 19.28.0 to 19.29.0</li>
<li class="">update jeap-spring-boot-jwe-starter from 1.22.0 to 1.23.0</li>
<li class="">update jeap-opensearch-index-type-registry-maven-plugin from 3.5.0 to 3.6.0</li>
<li class="">update jeap-spring-boot-starters from 24.19.0 to 24.20.0</li>
<li class="">update jeap-open-api-publisher from 7.19.0 to 7.20.0</li>
<li class="">update jeap-spring-boot-security-client-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-opensearch-searchitem-api from 2.18.0 to 2.19.0</li>
<li class="">update jeap-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-opensearch-client-starter from 2.18.0 to 2.19.0</li>
<li class="">update jeap-crypto from 10.18.0 to 10.19.0</li>
<li class="">update jeap-spring-boot-vault-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-messaging from 18.0.0 to 18.1.0</li>
<li class="">update jeap-server-sent-events from 12.17.0 to 12.18.0</li>
<li class="">update jeap-messaging-outbox from 17.17.0 to 17.18.0</li>
<li class="">update jeap-reaction-observer from 10.17.0 to 10.18.0</li>
<li class="">update jeap-messaging-sequential-inbox from 20.17.0 to 20.18.0</li>
<li class="">update jeap-spring-boot-security-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-audit from 10.16.0 to 10.17.0</li>
</ul>]]></content>
        <author>
            <name>jEAP Team</name>
            <uri>https://github.com/jeap-admin-ch</uri>
        </author>
        <category label="Release" term="Release"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[jeap-spring-boot-parent - Release 40.0.0]]></title>
        <id>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.0.0</id>
        <link href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.0.0"/>
        <updated>2026-08-21T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[New version 40.0.0 of jeap-spring-boot-parent is available.]]></summary>
        <content type="html"><![CDATA[<p>New version <a href="https://github.com/jeap-admin-ch/jeap-spring-boot-parent/blob/v40.0.0/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class=""><code>40.0.0</code></a> of <code>jeap-spring-boot-parent</code> is available.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="changed">Changed<a href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.0.0#changed" class="hash-link" aria-label="Direct link to Changed" title="Direct link to Changed" translate="no">​</a></h3>
<ul>
<li class="">update jeap-spring-boot-starters from 24.18.0 to 24.19.0<!-- -->
<ul>
<li class="">Fix failing token introspection when a client id contains colons by URL-encoding the client id and secret before
using them as basic auth credentials (see RFC 6749).</li>
</ul>
</li>
<li class="">update jeap-messaging from 17.16.0 to 18.0.0</li>
<li class="">Update parent from 8.13.0 to 9.0.0, which updates Avro from 1.12.1 to 1.12.2<!-- -->
<ul>
<li class="">Breaking test change: Major release because this parent updates jeap-messaging from 17.16.0 to 18.0.0, which
introduces the Avro class whitelist. Tests without a Spring context that build, serialize or deserialize a
generated Avro message have to install the whitelist themselves, see the notes below.</li>
</ul>
</li>
<li class="">Avro 1.12.2 only resolves classes from a schema when they are trusted, so jEAP Messaging installs an Avro
<code>ClassSecurityValidator</code> whitelist. Trusted are the Avro generated types in <code>ch.admin.bit.jeap</code> and - as long as
nothing is configured - in <code>ch.admin</code>, the common JDK collection and value types (<code>UUID</code>, <code>java.time</code>, the legacy
<code>java.util.Date</code> / <code>java.sql</code> date types) that a schema can reference via <code>java-class</code> / <code>java-key-class</code>, and
whatever <code>jeap.messaging.avro.trusted-packages</code> / <code>jeap.messaging.avro.trusted-classes</code> name - those regardless of
whether the class is Avro generated. Being an Avro generated type narrows the built-in packages, it never trusts a
class on its own.</li>
<li class="">Tests without a Spring context have to install the avro class whitelist themselves. A plain unit test that builds,
serializes or deserializes a generated Avro message now fails with <code>SecurityException: Forbidden ...</code> unless it
installs the whitelist first:<!-- -->
<div class="language-java codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-java codeBlock_bY9V thin-scrollbar" style="color:#bfc7d5;background-color:#292d3e"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#bfc7d5"><span class="token plain">@BeforeAll</span><br></div><div class="token-line" style="color:#bfc7d5"><span class="token plain">static void installAvroClassWhitelist() {</span><br></div><div class="token-line" style="color:#bfc7d5"><span class="token plain">    AvroClassSecurity.installDefaultIfMissing();</span><br></div><div class="token-line" style="color:#bfc7d5"><span class="token plain">}</span><br></div></code></pre></div></div>
</li>
</ul>]]></content>
        <author>
            <name>jEAP Team</name>
            <uri>https://github.com/jeap-admin-ch</uri>
        </author>
        <category label="Release" term="Release"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Welcome to the jEAP Blog]]></title>
        <id>https://jeap-admin-ch.github.io/blog/welcome-to-the-jeap-blog</id>
        <link href="https://jeap-admin-ch.github.io/blog/welcome-to-the-jeap-blog"/>
        <updated>2026-08-20T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Welcome to the jEAP blog! This is where we'll share announcements, release]]></summary>
        <content type="html"><![CDATA[<p>Welcome to the jEAP blog! This is where we'll share announcements, release
highlights and other news about the Java Enterprise Application Platform.</p>
<p>Stay tuned for upcoming posts.</p>]]></content>
        <author>
            <name>jEAP Team</name>
            <uri>https://github.com/jeap-admin-ch</uri>
        </author>
        <category label="Announcement" term="Announcement"/>
    </entry>
</feed>