dancan254/spring-boot-skills
v1.3.0MIT
Spring Boot 4 skills: scaffold, JPA, Redis, Kafka/RabbitMQ, security, DevOps, testing, OTel, Spring AI RAG, MCP servers, and legacy migration.
Changelog
All notable changes to this skill pack. Versions match the version field in every plugin manifest.
[Unreleased]
[1.3.0] - 2026-09-30
Added
pentest-auditskill: runtime pentest and security audit of a running app — OWASP ZAP DAST (baseline and OpenAPI-driven API scan,ghcr.io/zaproxy/zaproxy:2.17.0), a 10-probe manual checklist (headers, cookies, CORS, error leakage, actuator, JWT tampering, IDOR, method tampering, rate limiting) with OWASP mapping and severity table, and a verdict-first report template.security-hardeningkeeps build-time supply-chain scanning;not-*eval graders enforce the boundary in both directions.evals/routing suite forclaude plugin eval: one skill-fires case per skill (with not-the-neighbour graders where skills overlap), a Kafka-or-RabbitMQ ambiguity case, and 3 negative cases. The skill lint fails when a skill has no eval case expecting it to fire.scripts/RunEvals.java: run the routing suite on other agent CLIs (Kimi, Codex) — headless event-stream grading with the sametool_used/regexgraders, no judge model.
Changed
- Routing evals capped at 2 turns (was 3): the routing decision happens in the first turn, so the suite is ~50% cheaper per run ($6.69 → ~$3.30) with no signal lost.
scripts/lint-skills.pyandscripts/run-evals.pyported to Java 25 single-file source programs (java scripts/LintSkills.java) with a shared minimal JSON parser; CI installs Temurin 25 viasetup-java@v6.- The pentest eval prompt says "audit … for security vulnerabilities" rather than "pentest" — the literal word in a user turn trips Claude's cyber safeguards.
[1.2.0] - 2026-09-29
Changed
- Pins refreshed:
grafana/otel-lgtm0.34.0,redis8.10.2-alpine,ollama/ollama0.35.0,github/codeql-actionv4. - The skill lint also checks each image's Docker Hub verification command and the "confirm
<tag>" line before it. spring-testingemulates AWS with Floci (floci/floci:2.1.0,io.floci:*testcontainers-floci2.16.1, with@ServiceConnectionfor Spring Cloud AWS) instead of LocalStack, which now needs an auth token on every run.mongopinned to8.3.11; it floated onmongo:8.spring-testingusescom.redis.testcontainers.RedisContainerfor Redis, matchingredis-setup, instead of aGenericContainerthat@ServiceConnectiononly matched by image name.
Fixed
- Integration-test containers are Spring beans (
@TestConfiguration+@Bean @ServiceConnectioninIntegrationTestContainers, imported byBaseIntegrationTest) instead of@Testcontainers+static @Containerin the shared base class. The JUnit extension stopped the container after the first test class while Spring kept the cached context, so the second class failed withConnection refused— reproduced on Boot 4.1.1. Applies tospring-scaffold,spring-testing,spring-data-jpa,spring-ai-rag,redis-setup,kafka-setup, andrabbitmq-setup; the three messaging skills drop their own base classes and@DynamicPropertySourcewiring. spring-testingaudits for@Containerin shared base classes.security-hardeningreferencedaquasecurity/trivy-action@0.36.0, a tag that does not exist; it isv0.36.0.
[1.1.0] - 2026-09-29
Added
VERSIONS.mdas the single source of truth for every pin, andscripts/lint-skills.py, which fails when a skill disagrees with it or breaks frontmatter, reference, size, or neutrality rules.LintGitHub Actions workflow: skill lint plusclaude plugin validate.- Claude Code plugin and marketplace manifests (
.claude-plugin/). - Portable Agent Plugins manifest (
plugin.json) for Codex. CLAUDE.mdimportingAGENTS.mdfor contributors using Claude Code.- Install instructions for Claude Code, Codex, and Kimi Code CLI.
Changed
- Skill bodies and
AGENTS.mdare tool-neutral; tool-specific steps live inREADME.mdonly. - Every skill description trimmed to ~290–340 characters, with a "not for X, use Y" clause where skills overlap, and "Maven" stated for the Maven-only skills.
kafka-setupandrabbitmq-setupask which broker to use when the request doesn't name one.spring-securityverifies the project's Boot version against the latest 4.x GA.spring-scaffoldcut from 904 to 428 lines: fixed file content moved toassets/templates/, and the Dockerfile, CI, and OTLP log-export steps now hand off todevops-scaffoldandotel-setup.spring-scaffolddefaultsoutputDirto./<name>in the current directory, states its Lombok/PostgreSQL/OTel defaults up front, and acceptslombok: falseandotel: false.devops-scaffoldCI cancels superseded runs (concurrency), carried over from the scaffold's copy.
Fixed
- Redis image pinned to
8.8.3-alpineeverywhere;devops-scaffoldandspring-testingfloated on8-alpine. - All three manifests share one description.
Removed
articleskill. The pack is engineering-only.
[1.0.0]
- Initial release for Kimi Code CLI: 14 Spring Boot 4 engineering skills plus
article.