<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="rss.xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>jEAP Blog</title>
        <link>https://jeap-admin-ch.github.io/blog</link>
        <description>jEAP Blog</description>
        <lastBuildDate>Tue, 25 Aug 2026 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <item>
            <title><![CDATA[jeap-spring-boot-parent - Release 40.2.0]]></title>
            <link>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.2.0</link>
            <guid>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.2.0</guid>
            <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[New version 40.2.0 of jeap-spring-boot-parent is available.]]></description>
            <content:encoded><![CDATA[<p>New version <a href="https://github.com/jeap-admin-ch/jeap-spring-boot-parent/blob/v40.2.0/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class=""><code>40.2.0</code></a> of <code>jeap-spring-boot-parent</code> is available.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="changed">Changed<a href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.2.0#changed" class="hash-link" aria-label="Direct link to Changed" title="Direct link to Changed" translate="no">​</a></h3>
<ul>
<li class="">update jeap-opensearch-client-starter from 2.19.0 to 2.20.0</li>
<li class="">Exclude the optional Jackson 2 core and databind dependencies from the OpenSearch Java client.</li>
</ul>]]></content:encoded>
            <category>Release</category>
        </item>
        <item>
            <title><![CDATA[jeap-spring-boot-parent - Release 40.1.0]]></title>
            <link>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.1.0</link>
            <guid>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.1.0</guid>
            <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[New version 40.1.0 of jeap-spring-boot-parent is available.]]></description>
            <content:encoded><![CDATA[<p>New version <a href="https://github.com/jeap-admin-ch/jeap-spring-boot-parent/blob/v40.1.0/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class=""><code>40.1.0</code></a> of <code>jeap-spring-boot-parent</code> is available.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="changed">Changed<a href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.1.0#changed" class="hash-link" aria-label="Direct link to Changed" title="Direct link to Changed" translate="no">​</a></h3>
<ul>
<li class="">Update parent from 9.0.0 to 9.0.1</li>
<li class="">update jeap-spring-boot-tls-starter from 19.27.0 to 19.28.0</li>
<li class="">update jeap-opensearch-index-type from 1.24.0 to 1.25.0</li>
<li class="">update jeap-db-schema-publisher from 3.28.0 to 3.29.0</li>
<li class="">update jeap-spring-boot-roles-anywhere-starter from 3.29.0 to 3.30.0</li>
<li class="">update jeap-spring-boot-db-migration-starter from 19.27.0 to 19.28.0</li>
<li class="">update jeap-spring-boot-config-aws-starter from 19.28.0 to 19.29.0</li>
<li class="">update jeap-spring-boot-jwe-starter from 1.22.0 to 1.23.0</li>
<li class="">update jeap-opensearch-index-type-registry-maven-plugin from 3.5.0 to 3.6.0</li>
<li class="">update jeap-spring-boot-starters from 24.19.0 to 24.20.0</li>
<li class="">update jeap-open-api-publisher from 7.19.0 to 7.20.0</li>
<li class="">update jeap-spring-boot-security-client-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-opensearch-searchitem-api from 2.18.0 to 2.19.0</li>
<li class="">update jeap-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-opensearch-client-starter from 2.18.0 to 2.19.0</li>
<li class="">update jeap-crypto from 10.18.0 to 10.19.0</li>
<li class="">update jeap-spring-boot-vault-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-messaging from 18.0.0 to 18.1.0</li>
<li class="">update jeap-server-sent-events from 12.17.0 to 12.18.0</li>
<li class="">update jeap-messaging-outbox from 17.17.0 to 17.18.0</li>
<li class="">update jeap-reaction-observer from 10.17.0 to 10.18.0</li>
<li class="">update jeap-messaging-sequential-inbox from 20.17.0 to 20.18.0</li>
<li class="">update jeap-spring-boot-security-starter from 24.19.0 to 24.20.0</li>
<li class="">update jeap-audit from 10.16.0 to 10.17.0</li>
</ul>]]></content:encoded>
            <category>Release</category>
        </item>
        <item>
            <title><![CDATA[jeap-spring-boot-parent - Release 40.0.0]]></title>
            <link>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.0.0</link>
            <guid>https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.0.0</guid>
            <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[New version 40.0.0 of jeap-spring-boot-parent is available.]]></description>
            <content:encoded><![CDATA[<p>New version <a href="https://github.com/jeap-admin-ch/jeap-spring-boot-parent/blob/v40.0.0/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class=""><code>40.0.0</code></a> of <code>jeap-spring-boot-parent</code> is available.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="changed">Changed<a href="https://jeap-admin-ch.github.io/blog/jeap-spring-boot-parent-40.0.0#changed" class="hash-link" aria-label="Direct link to Changed" title="Direct link to Changed" translate="no">​</a></h3>
<ul>
<li class="">update jeap-spring-boot-starters from 24.18.0 to 24.19.0<!-- -->
<ul>
<li class="">Fix failing token introspection when a client id contains colons by URL-encoding the client id and secret before
using them as basic auth credentials (see RFC 6749).</li>
</ul>
</li>
<li class="">update jeap-messaging from 17.16.0 to 18.0.0</li>
<li class="">Update parent from 8.13.0 to 9.0.0, which updates Avro from 1.12.1 to 1.12.2<!-- -->
<ul>
<li class="">Breaking test change: Major release because this parent updates jeap-messaging from 17.16.0 to 18.0.0, which
introduces the Avro class whitelist. Tests without a Spring context that build, serialize or deserialize a
generated Avro message have to install the whitelist themselves, see the notes below.</li>
</ul>
</li>
<li class="">Avro 1.12.2 only resolves classes from a schema when they are trusted, so jEAP Messaging installs an Avro
<code>ClassSecurityValidator</code> whitelist. Trusted are the Avro generated types in <code>ch.admin.bit.jeap</code> and - as long as
nothing is configured - in <code>ch.admin</code>, the common JDK collection and value types (<code>UUID</code>, <code>java.time</code>, the legacy
<code>java.util.Date</code> / <code>java.sql</code> date types) that a schema can reference via <code>java-class</code> / <code>java-key-class</code>, and
whatever <code>jeap.messaging.avro.trusted-packages</code> / <code>jeap.messaging.avro.trusted-classes</code> name - those regardless of
whether the class is Avro generated. Being an Avro generated type narrows the built-in packages, it never trusts a
class on its own.</li>
<li class="">Tests without a Spring context have to install the avro class whitelist themselves. A plain unit test that builds,
serializes or deserializes a generated Avro message now fails with <code>SecurityException: Forbidden ...</code> unless it
installs the whitelist first:<!-- -->
<div class="language-java codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-java codeBlock_bY9V thin-scrollbar" style="color:#bfc7d5;background-color:#292d3e"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#bfc7d5"><span class="token plain">@BeforeAll</span><br></div><div class="token-line" style="color:#bfc7d5"><span class="token plain">static void installAvroClassWhitelist() {</span><br></div><div class="token-line" style="color:#bfc7d5"><span class="token plain">    AvroClassSecurity.installDefaultIfMissing();</span><br></div><div class="token-line" style="color:#bfc7d5"><span class="token plain">}</span><br></div></code></pre></div></div>
</li>
</ul>]]></content:encoded>
            <category>Release</category>
        </item>
        <item>
            <title><![CDATA[Welcome to the jEAP Blog]]></title>
            <link>https://jeap-admin-ch.github.io/blog/welcome-to-the-jeap-blog</link>
            <guid>https://jeap-admin-ch.github.io/blog/welcome-to-the-jeap-blog</guid>
            <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Welcome to the jEAP blog! This is where we'll share announcements, release]]></description>
            <content:encoded><![CDATA[<p>Welcome to the jEAP blog! This is where we'll share announcements, release
highlights and other news about the Java Enterprise Application Platform.</p>
<p>Stay tuned for upcoming posts.</p>]]></content:encoded>
            <category>Announcement</category>
        </item>
    </channel>
</rss>