spring-projects/spring-security · warning

**** You are advised to use Spring

Error message

**** You are advised to use Spring %s or later with this version. You are running: %s

What it means

SpringSecurityCoreVersion.performVersionChecks compares the Spring Framework version on the classpath with the minimum Spring version this Spring Security release was built against. If the runtime Spring version is older than the minimum, it warns that the combination is unsupported and upgrading is advised.

Solutions

  1. Upgrade spring-framework (spring-core etc.) to at least the stated minimum version
  2. Use the Spring Security BOM together with the matching Spring Boot / Framework BOM so versions align
  3. Run mvn dependency:tree (or gradle dependencies) to find what is pinning the old Spring version and exclude/align it

Example fix

<!-- before -->
<dependency>
  <groupId>org.springframework</groupId>
  <artifactId>spring-core</artifactId>
  <version>5.3.0</version>
</dependency>
<!-- after: align via BOM -->
<dependencyManagement>
  <dependencies>
    <dependency>
      <groupId>org.springframework</groupId>
      <artifactId>spring-framework-bom</artifactId>
      <version>6.1.0</version>
      <type>pom</type>
      <scope>import</scope>
    </dependency>
  </dependencies>
</dependencyManagement>
Defensive patterns

Strategy: validation

Validate before calling

// Check alignment at build time
String spring = SpringVersion.getVersion();
String min = "6.1.0"; // minSpringVersion of your Spring Security release
if (new ComparableVersion(spring).compareTo(new ComparableVersion(min)) < 0) {
  throw new GradleException("Upgrade spring-framework to >= " + min);
}

Prevention

When it happens

Trigger: performVersionChecks runs at startup (via spring-security-core's static init) and finds springVersion < minSpringVersion, e.g. Spring Security 6.x running against an old Spring Framework 5.x jar.

Common situations: Partial dependency upgrades where spring-security-core was bumped but spring-framework-core was not; dependencyManagement pinning an old Spring version; classpath conflicts pulling an older Spring jar transitively.

Understand the failure class

Background: "is not a compatible type" / "cannot merge" errors: when a value's type doesn't match what the library requires — this error's family across 65 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/95d5d5366079e40d. Report an issue: GitHub.

Appendix: source

Thrown at core/src/main/java/org/springframework/security/core/SpringSecurityCoreVersion.java:81

	/**
	 * Perform version checks with specific min Spring Version.
	 * @param minSpringVersion
	 */
	private static void performVersionChecks(@Nullable String minSpringVersion) {
		if (minSpringVersion == null) {
			return;
		}
		// Check Spring Compatibility
		String springVersion = SpringVersion.getVersion();
		String version = getVersion();
		if (disableChecks(springVersion, version)) {
			return;
		}
		// should be disabled if springVersion is null
		Assert.notNull(springVersion, "springVersion cannot be null");
		logger.info("You are running with Spring Security Core " + version);
		if (new ComparableVersion(springVersion).compareTo(new ComparableVersion(minSpringVersion)) < 0) {
			logger.warn("**** You are advised to use Spring " + minSpringVersion
					+ " or later with this version. You are running: " + springVersion);
		}
	}

	public static @Nullable String getVersion() {
		Package pkg = SpringSecurityCoreVersion.class.getPackage();
		return (pkg != null) ? pkg.getImplementationVersion() : null;
	}

	/**
	 * Disable if springVersion and springSecurityVersion are the same to allow working
	 * with Uber Jars.
	 * @param springVersion
	 * @param springSecurityVersion
	 * @return
	 */
	private static boolean disableChecks(@Nullable String springVersion, @Nullable String springSecurityVersion) {
		if (springVersion == null || springVersion.equals(springSecurityVersion)) {

View on GitHub (pinned to 96852e8860)