spring-projects/spring-security · warning
**** You are advised to use Spring
Error message
**** You are advised to use Spring %s or later with this version. You are running: %s
What it means
SpringSecurityCoreVersion.performVersionChecks compares the Spring Framework version on the classpath with the minimum Spring version this Spring Security release was built against. If the runtime Spring version is older than the minimum, it warns that the combination is unsupported and upgrading is advised.
Solutions
- Upgrade spring-framework (spring-core etc.) to at least the stated minimum version
- Use the Spring Security BOM together with the matching Spring Boot / Framework BOM so versions align
- Run mvn dependency:tree (or gradle dependencies) to find what is pinning the old Spring version and exclude/align it
Example fix
<!-- before -->
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-core</artifactId>
<version>5.3.0</version>
</dependency>
<!-- after: align via BOM -->
<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-framework-bom</artifactId>
<version>6.1.0</version>
<type>pom</type>
<scope>import</scope>
</dependency>
</dependencies>
</dependencyManagement> Defensive patterns
Strategy: validation
Validate before calling
// Check alignment at build time
String spring = SpringVersion.getVersion();
String min = "6.1.0"; // minSpringVersion of your Spring Security release
if (new ComparableVersion(spring).compareTo(new ComparableVersion(min)) < 0) {
throw new GradleException("Upgrade spring-framework to >= " + min);
} Prevention
- Import spring-framework-bom and spring-security-bom from the same release train (or Spring Boot)
- Never pin spring-core to an ad-hoc version in dependencyManagement
- Check mvn dependency:tree for conflicting Spring versions after upgrades
When it happens
Trigger: performVersionChecks runs at startup (via spring-security-core's static init) and finds springVersion < minSpringVersion, e.g. Spring Security 6.x running against an old Spring Framework 5.x jar.
Common situations: Partial dependency upgrades where spring-security-core was bumped but spring-framework-core was not; dependencyManagement pinning an old Spring version; classpath conflicts pulling an older Spring jar transitively.
Understand the failure class
Background: "is not a compatible type" / "cannot merge" errors: when a value's type doesn't match what the library requires — this error's family across 65 libraries.
Related errors
- A Bean named mvcHandlerMappingIntrospector of type…
- A Bean named mvcHandlerMappingIntrospector of type…
- A filter chain that matches any request
- A ReactiveSessionRegistry is needed for concurrent session…
- A ServerOneTimeTokenGenerationSuccessHandler is required to…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/95d5d5366079e40d.
Report an issue: GitHub.
Appendix: source
Thrown at core/src/main/java/org/springframework/security/core/SpringSecurityCoreVersion.java:81
/**
* Perform version checks with specific min Spring Version.
* @param minSpringVersion
*/
private static void performVersionChecks(@Nullable String minSpringVersion) {
if (minSpringVersion == null) {
return;
}
// Check Spring Compatibility
String springVersion = SpringVersion.getVersion();
String version = getVersion();
if (disableChecks(springVersion, version)) {
return;
}
// should be disabled if springVersion is null
Assert.notNull(springVersion, "springVersion cannot be null");
logger.info("You are running with Spring Security Core " + version);
if (new ComparableVersion(springVersion).compareTo(new ComparableVersion(minSpringVersion)) < 0) {
logger.warn("**** You are advised to use Spring " + minSpringVersion
+ " or later with this version. You are running: " + springVersion);
}
}
public static @Nullable String getVersion() {
Package pkg = SpringSecurityCoreVersion.class.getPackage();
return (pkg != null) ? pkg.getImplementationVersion() : null;
}
/**
* Disable if springVersion and springSecurityVersion are the same to allow working
* with Uber Jars.
* @param springVersion
* @param springSecurityVersion
* @return
*/
private static boolean disableChecks(@Nullable String springVersion, @Nullable String springSecurityVersion) {
if (springVersion == null || springVersion.equals(springSecurityVersion)) {View on GitHub (pinned to 96852e8860)