Skip to content
CAI
Software that uses CAICheck a score

spring-projects/spring-data-ldap

60.9

Adequate · 21 September 2026

3.3k

lines of production code

Java

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Spring Data LDAP module that provides a repository abstraction for interacting with LDAP directories. It enables developers to bind Java objects to LDAP entries, perform CRUD operations, and execute queries with support for parameter encoding and result projection. The library integrates with both Spring and CDI environments, offering XML namespace configuration and modern build infrastructure.

How it got here

2016 — Spring Data 4.2 migration and LDAP enhancements

15 changes.

The project migrated to Spring Data 4.2 and Jakarta EE namespaces, upgrading core dependencies and build infrastructure. Significant features were added to the LDAP repository module, including parameter encoding, result projection, and XML namespace support, accompanied by a comprehensive test suite migration to JUnit 5.

2017–2023 — CDI integration and mapping infrastructure

6 changes.

This period focused on establishing the core LDAP mapping infrastructure for object-to-directory binding and introducing CDI support to allow LDAP repositories to be discovered and injected within CDI containers. The work included implementing the necessary extension classes and persistent entity metadata, alongside comprehensive integration and unit tests to validate the new functionality. Maintenance activities included updating the Maven wrapper and migrating the build system to use Spring Develocity conventions.

Features

Added XML schema for LDAP repository configuration

A new XML schema file (spring-ldap-1.0.xsd) has been added to define the structure for LDAP repository configuration. This schema introduces a 'repositories' element that extends standard repository attributes and adds an 'ldap-template-ref' attribute, allowing users to specify a reference to an LdapTemplate bean when configuring LDAP repositories via XML.

src/main/resources/org · high confidence

CDI support for LDAP repositories

This change introduces a new CDI extension that allows Spring Data LDAP repositories to be exported and discovered by a CDI container. The new \LdapRepositoryExtension\ scans for \LdapOperations\ beans and registers corresponding repository beans, while \LdapRepositoryBean\ handles the instantiation of these repositories by injecting the appropriate LDAP operations context. This enables users to inject LDAP repositories directly into CDI-managed beans.

src/main/java/org/springframework/data/ldap/repository/cdi · high confidence

LdapRepository now extends ListCrudRepository with new parameter encoding support

The LdapRepository interface has been upgraded to extend ListCrudRepository instead of CrudRepository, changing the return types of findOne() to Optional and findAll() to List for better integration with modern Spring Data patterns. Additionally, a new @LdapEncode annotation and LdapEncoder strategy interface have been introduced, allowing users to configure custom encoding for LDAP query parameters to prevent injection attacks while supporting specific use cases like LIKE queries through the built-in LikeEncoder.

src/main/java/org/springframework/data/ldap/repository · high confidence

New LDAP mapping infrastructure for object-to-directory binding

This change introduces the core mapping subsystem for Spring Data LDAP, enabling the binding of Java objects to LDAP entries. It adds \LdapMappingContext\ to manage entity metadata, \LdapPersistentEntity\ and \BasicLdapPersistentEntity\ to represent LDAP-specific object structures, and \LdapPersistentProperty\ to handle property-level details (such as identifying the \@Id\ field). The package also includes \LdapSimpleTypes\ to define supported simple types (like \javax.naming.Name\) and adopts JSpecify annotations for nullability constraints.

src/main/java/org/springframework/data/ldap/core · high confidence

Spring LDAP namespace support and CDI extension registration

Users can now use the Spring LDAP XML namespace (http://www.springframework.org/schema/data/ldap) in configuration files, with the corresponding schema and handler registered in spring.handlers and spring.schemas. The LdapRepositoryFactory is automatically registered via spring.factories, enabling Spring Data LDAP repository support without manual configuration. Additionally, a CDI extension (LdapRepositoryExtension) is registered for Jakarta EE environments, allowing LDAP repository integration in CDI-based applications.

src/main/resources/META-INF · high confidence

XML namespace support for LDAP repository configuration

Users can now configure Spring Data LDAP repositories using XML by registering the new LdapNamespaceHandler, which registers a bean definition parser for the 'repositories' element to bootstrap LDAP repository infrastructure. The package also adopts JSpecify annotations for nullability constraints.

src/main/java/org/springframework/data/ldap/config · high confidence

Behavioural changes

LDAP repository configuration gains base class, name generator, and nested repository support

The \@EnableLdapRepositories\ annotation now supports configuring a custom \repositoryBaseClass\ to define the base type for repository proxies, a \nameGenerator\ to control bean naming during discovery, and a \considerNestedRepositories\ flag to include inner-class repository interfaces. Additionally, the configuration infrastructure registers a shared \LdapMappingContext\ bean by default and ensures that reactive repository interfaces are excluded from standard LDAP repository processing.

src/main/java/org/springframework/data/ldap/repository/config · high confidence

LDAP repository query execution now supports result projection and value expressions

LDAP repository queries now support dynamic result projection and value expressions in \@Query\ annotations. The query execution layer has been refactored to use a new \LdapQueryExecution\ strategy that applies a \ResultProcessingConverter\ to map LDAP results to DTOs or other target types. Additionally, the \StringBasedQuery\ parser now evaluates value expressions (e.g., \\#{...}\) within query strings, and the \LdapParameters\ class exposes a custom \LdapParameter\ implementation that respects the new \@LdapEncode\ annotation for parameter encoding.

src/main/java/org/springframework/data/ldap/repository/query · high confidence

Migrate build to Spring Develocity Conventions extension

The Maven build now uses the Spring Develocity Conventions extension (version 0.0.26) to manage build behavior and reporting. Additionally, the JVM configuration has been updated to include specific module exports and opens for the JDK compiler and base libraries, ensuring compatibility with the new build conventions.

.mvn · high confidence

Project documentation and build infrastructure overhaul

The project documentation has been migrated from Markdown to AsciiDoc, introducing a new README.adoc with updated Maven configuration examples and a dedicated SECURITY.adoc for vulnerability reporting. The legacy Travis CI configuration (.travis.yml) and the old CODE\_OF\_CONDUCT.adoc have been removed in favor of a new CI.adoc that documents local execution via Docker and act, and a reference to the standard Spring Code of Conduct. Additionally, the Maven Wrapper scripts (mvnw, mvnw.cmd) and license file (LICENSE.txt) have been added to standardize builds, while the CONTRIBUTING.adoc link has been updated to point to the main branch.

(repo-wide) · high confidence

Refactored LDAP repository support to use Querydsl fragments and updated entity information

The repository support infrastructure in \src/main/java/org/springframework/data/ldap/repository/support\ has been refactored to align with modern Spring Data patterns. \QueryDslLdapRepository\ is now deprecated in favor of \QuerydslLdapPredicateExecutor\, which is injected as a repository fragment via \LdapRepositoryFactory\ rather than being a base class. \SimpleLdapRepository\ and \LdapRepositoryFactory\ have been updated to accept and use a \MappingContext\, and \LdapEntityInformation\ now correctly implements \EntityInformation\ using \javax.naming.Name\ as the ID type. Additionally, the \LdapRepositoryFactoryBean\ now supports configuring a custom \MappingContext\.

src/main/java/org/springframework/data/ldap/repository/support · high confidence

Test coverage

Add unit tests for QuerydslLdapPredicateExecutor and migrate test suite to JUnit 5; Added and migrated tests for LDAP repository configuration; Added integration tests for the LDAP CDI repository extension; Added test infrastructure for LDAP configuration and namespace handling; Added test resources for LDAP namespace and repository configuration; Added tests for LDAP repository query features and migrated to JUnit 5; Added unit tests for LDAP repository components; Added unit tests for LdapMappingContext and LdapPersistentProperty.

Dependencies

Updated Maven Wrapper to version 3.9.16

The Maven Wrapper configuration has been updated to use Apache Maven 3.9.16. This ensures that builds are executed with a consistent, specific version of Maven, improving reproducibility and potentially providing access to the latest features and bug fixes available in that release.

.mvn/wrapper · high confidence

Upgrade to Spring Data 4.2 and Spring LDAP 4.2 with Jakarta EE migration

The project has been upgraded to version 4.2.0-SNAPSHOT, aligning with Spring Data 4.2 and Spring LDAP 4.2. This release includes a migration to Jakarta EE namespaces (e.g., \jakarta.enterprise.cdi-api\), replaces the \spring-web\ dependency with \spring-tx\, and switches the Querydsl dependency from \querydsl-mongodb\ to \querydsl-core\. Additionally, the documentation build system has moved to Antora, introducing new npm dependencies for the documentation site and replacing the previous Asciidoctor Maven plugin configuration.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 64 → 61 (-3.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.6)
  • Architecture 100 → 66 (-34.3)
  • Maturity 56 → 57 (+1.7)
  • Readiness 57 → 59 (+2.5)
  • Security 74 → 61 (-12.4)

Resolved (14)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Further orphaned files (smaller)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • The getting started example shows only a PersonRepository interface with findByLastname, but it does not demonstrate how to configure Spring Data LDAP (e.g. bean registration or XML namespace setup). (README.adoc)

New (56)

  • Coverage not measured — no coverage collector is wired up
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no architecture or design documentation (README.adoc)
  • Documentation: no installation or build instructions (README.adoc)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 36 more

Changes since last survey

  • 10 commits — 10 feature/other, 0 fixes

By area

  • (root) — 5 commits
  • (repo) — 2 commits
  • .github/workflows — 1 commit
  • .mvn/extensions.xml — 1 commit
  • src/main — 1 commit

Notable commits

  • change: Add release train automation.
  • change: Build against Spring LDAP 4.1.1-SNAPSHOT.
  • change: Build against Spring LDAP 4.2 snapshots.
  • change: Enter rampdown phase for 4.2.0-M1.
  • change: Enter rampdown phase for 4.2.0-M2.
  • change: Prepare next development iteration.
  • change: Release version 4.2.0-M1 (2026.1.0).
  • change: Update Maven extensions.
  • change: Update build config for correct notice and license.txt inclusion.
  • change: Upgrade to Spring LDAP 4.1.1

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

spring-projects/spring-data-ldap was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 50ce0ed2c1843229204671c62208c87dcb3ffaca — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.