Back to Discover

#java

1 prompt found

Spring Boot 2.7 to 3.x Migration Planner: Java 17 Baseline, javax to jakarta Imports, Spring Security 6 SecurityFilterChain and requestMatchers, Hibernate 6 Sequence Naming, Trailing Slash Matching, properties-migrator, and OpenRewrite
๐Ÿ’ป Coding

Spring Boot 2.7 to 3.x Migration Planner: Java 17 Baseline, javax to jakarta Imports, Spring Security 6 SecurityFilterChain and requestMatchers, Hibernate 6 Sequence Naming, Trailing Slash Matching, properties-migrator, and OpenRewrite

PpromptstudioยทOct 7, 2026
No rating

Upgrade a Spring Boot 2.7 service to 3.x in safe steps: move to Java 17, swap javax imports for jakarta without touching Java SE packages, replace WebSecurityConfigurerAdapter with a SecurityFilterChain bean, handle Hibernate 6 sequence and query changes, decide what to do about trailing slash URLs, find renamed properties, and let OpenRewrite do the mechanical edits.

Act as a senior Java backend engineer who has migrated dozens of Spring Boot 2.7 services to 3.x, runs OpenRewrite recipes before touching code by hand, and has seen a release fail because Hibernate 6 started looking for a different sequence name. Inputs: - Build file with Spring Boot, Java, and third party dependency versions (pom.xml or build.gradle): [BuildFile] - Current Spring Security configuration code: [SecurityConfig] - JPA usage: ID generation strategies, database, native queries, custom types: [JpaUsage] - Web endpoints and clients that call them, including any that use trailing slashes: [WebEndpoints] - Integrations: tracing, API docs, caching, messaging libraries: [Integrations] - Target Boot version and test setup: [TargetAndTests] - Output format: [Format] Generate: 1. A phased plan: upgrade to the latest 2.7.x and clear deprecation warnings first, then Java 17 on 2.7, then Boot 3.x. Mark the target from TargetAndTests and note that later 3.x lines and Boot 4 may change more; check your version notes. 2. An OpenRewrite step: the rewrite-spring recipe for Boot 3 (for example org.openrewrite.java.spring.boot3.UpgradeSpringBoot_3_0 or a later 3.x recipe) run with the Maven or Gradle plugin on a branch, then a review of the diff. 3. A javax to jakarta map: javax.persistence, javax.servlet, javax.validation, javax.annotation (where Jakarta), and javax.transaction move to jakarta.*; Java SE packages such as javax.sql and javax.crypto stay as they are. 4. A dependency table from BuildFile and Integrations: each library, its Jakarta compatible version or replacement (for example springfox to springdoc-openapi 2.x, Spring Cloud Sleuth to Micrometer Tracing), and a blocker column. 5. Spring Security 6 rewrite of SecurityConfig: WebSecurityConfigurerAdapter is gone, so expose a SecurityFilterChain bean; authorizeRequests becomes authorizeHttpRequests; antMatchers and mvcMatchers become requestMatchers; @EnableGlobalMethodSecurity becomes @EnableMethodSecurity. Show before and after code. 6. Hibernate 6 checks from JpaUsage: the default sequence naming change for GenerationType.AUTO or SEQUENCE (per entity sequences instead of one shared hibernate_sequence), the legacy naming setting to keep the old behavior during migration, query syntax issues in HQL, and custom @Type mappings. 7. Trailing slash matching: Spring Framework 6 no longer matches /orders/ to /orders by default. From WebEndpoints, list affected clients and pick a fix: update clients, map both paths, or use a URL handler filter where your Framework version provides it. 8. Properties: add spring-boot-properties-migrator at runtime during the migration to log renamed keys (for example spring.redis.* to spring.data.redis.*), then remove it. 9. A test and release checklist: compile, unit and integration tests, security tests for each protected path, a database migration test against a copy of production schema, and a canary release. Constraints: - Base every change on the Inputs; never claim a library version exists without telling the user to confirm it on Maven Central. - Show code in Java. No em dashes.