Rob Winch

Rob Winch

Rob Winch is employed by VMware as the project lead of security related projects within Spring. He is also a committer on the core Spring Framework and co-author for Spring Security LiveLessons and a Spring Security book. In the past he has worked in the health care industry, bioinformatics research, high performance computing, and as a web consultant. When he is not sitting in front of a computer he enjoys cycling with his friends.

Recent Blog posts by Rob Winch

Spring Session Apple SR3 Released

Releases | June 14, 2018 | ...
This post was authored by Vedran Pavić On behalf of the community I’m pleased to announce the release of Spring Session BOM Apple-SR3. This release includes an update of Spring Session core modules (which include Data Redis, Hazelcast and JDBC) to 2.0.4.RELEASE. The following table provides an overview of all the included modules and their respective versions: Module Version Spring Session Core 2.0.4.RELEASE Spring Session Data GemFire 2.0.2.RELEASE Spring Session Data Geode 2.0.2.RELEASE Spring Session Data MongoDB 2.0.2.RELEASE Spring Session Data Redis 2.0.4.RELEASE Spring Session Hazelcast…

Spring Security 5.0.6 and 4.2.7 Released

Releases | June 13, 2018 | ...
On behalf of the community, I am pleased to announce that the Spring Security 5.0.6 (changelog) and 4.2.7 (changelog) have been released. The releases primarily delivers bug fixes and dependency version updates along with some minor improvements. The releases will be found in the upcoming Spring Boot maintenance releases coming later this week. Project Site | Reference | Help

Spring Security 5.1.0.M1 Released

Releases | May 15, 2018 | ...
On behalf of the community I’m pleased to announce the release of Spring Securiity 5.1.0.M1. This release resolves over 80 tickets. The highlights can be seen below: Spring Security OAuth2 Client Support for WebFlux. See the sample for how to use it. Numerous other enhancements to WebFlux Support Added OAuth2ClientArgumentResolver Implementation of the Authorization Code Grant. See the sample for how to use it. Feedback Please If you have feedback on this release, I encourage you to reach out via StackOverflow, GitHub Issues, or via the comments section. You can also ping me @rob_winch , Joe…

Spring Security 4.2.6 Released

Releases | May 08, 2018 | ...
I'm pleased to announce the release of Spring Security 4.2.6. The release primarily delivers bug fixes and dependency version updates along with some minor improvements. For a complete list of changes, please refer to the 4.2.6 changelog. Project Site | Reference | Help

Spring Session Apple SR2

Releases | May 08, 2018 | ...
On behalf of the community I’m pleased to announce the release of Spring Session BOM Apple-SR2. This release includes an update to the core modules and adds support for Spring Session for Apache Geode. You can use the BOM With Maven: With Gradle: Project Page | Stack Overflow | Gitter

Spring Security SAML Roadmap

Engineering | March 05, 2018 | ...
The Spring Security SAML project has been an integral part of the Spring ecosystem since its inception nearly 9 years ago. This critically important project was born through the incredible effort and contributions of Vladimír Schäfer. I’d like to take the time to personally thank Vladimír and our fantastic community for their tireless work. Without all of their efforts, this project would not be what it is today. Vladimír, our amazing community, and the Spring engineering team are planning to team up to enhance Spring Security SAML to achieve the following primary goals: Ensuring all…

Spring Security SAML and this week's SAML Vulnerability

Engineering | March 01, 2018 | ...
This week, the software world found out that SAML Vulnerabilities Affecting Multiple Implementations were discovered. If you use Spring Security SAML’s defaults, you are not impacted by this vulnerability. The underlying implementation that Spring Security SAML uses is Shibboleth’s OpenSAML Java library. The OpenSAML Java implementation was not listed in the libraries that contain the vulnerability (Shibboleth openSAML C++ was vulnerable). However, if the ParserPool has been customized, you may be impacted. NOT Safe Configurations Specifically, if the application explicitly sets the…

Spring Session Apple SR1 Released

Releases | March 01, 2018 | ...
This post was authored by Vedran Pavić On behalf of the community I’m pleased to announce the release of Spring Session BOM Apple-SR1. With the changes to Spring Session modules described in 2.0.0.RELEASE announcement, the addition of bill of materials (BOM) module was a logical next step. Note The originally released Apple-RELEASE contained a glitch in published BOM so make sure you use Apple-SR1. The BOM provides dependency management for Spring Session core modules (which include Data Redis, Hazelcast and JDBC) and Spring Session Data MongoDB. The following table provides an overview of all…

Spring Security 5.0.3 Released

Releases | February 28, 2018 | ...
I’m pleased to announce the release of Spring Security 5.0.3. The main purpose of this release is to provide a significant performance improvement for Spring Security WebFlux. It also contains dependency updates to prepare for Spring Boot 2.0.0.RELEASE. For a complete list of changes, refer to the changelog. Project Site | Reference | Help

Spring Security 5.0.2 Released

Releases | February 20, 2018 | ...
I’m pleased to announce the release of Spring Security 5.0.2. This release fixes a number of bugs and updates to dependency versions to align with Spring Boot’s upcoming release. It also includes some changes to work with Jackson 2.9.4. For a complete list of changes, refer to the changelog. Project Site | Reference | Help

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all