{"id":785050,"date":"2026-07-07T01:32:09","date_gmt":"2026-07-07T01:32:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/785050\/"},"modified":"2026-07-07T01:32:09","modified_gmt":"2026-07-07T01:32:09","slug":"java-news-roundup-strict-field-initialization-glassfish-graalvm-jreleaser-refactorfirst","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/785050\/","title":{"rendered":"Java News Roundup: Strict Field Initialization, GlassFish, GraalVM, JReleaser, RefactorFirst"},"content":{"rendered":"<p>This week&#8217;s Java roundup for June 29th, 2026, features news highlighting: a new JEP candidate, Strict Field Initialization; point releases of GraalVM, JReleaser, RefactorFirst and Java Operator SDK; maintenance releases of GlassFish and Micronaut; the second milestone release of Grails 8.0; and the beta release of Open Liberty 26.0.0.7.<\/p>\n<p>OpenJDK<\/p>\n<p>JEP 539, <a href=\"https:\/\/openjdk.org\/jeps\/539\" rel=\"nofollow noopener\" target=\"_blank\">Strict Field Initialization in the JVM (Preview)<\/a>, has been <a href=\"https:\/\/mail.openjdk.org\/archives\/list\/jdk-dev@openjdk.org\/thread\/FGQVFIUNYX4GVJTABNLPFBLBLKDPM55H\/\" rel=\"nofollow noopener\" target=\"_blank\">elevated<\/a> from its JEP Draft 8350458 to Candidate status. This JEP introduces strictly-initialized fields in the Java Virtual Machine that are required to be initialized before they are read. Therefore, default values such as 0 or null are never observed. This feature is available for use by compilers that emit class files.<\/p>\n<p>JDK 27<\/p>\n<p><a href=\"https:\/\/github.com\/openjdk\/jdk\/releases\/tag\/jdk-27%2B29\" rel=\"nofollow noopener\" target=\"_blank\">Build 29<\/a> of the JDK 27 <a href=\"https:\/\/jdk.java.net\/27\/\" rel=\"nofollow noopener\" target=\"_blank\">early-access builds<\/a> was made available this past week featuring <a href=\"https:\/\/github.com\/openjdk\/jdk\/compare\/jdk-27%2B28...jdk-27%2B29\" rel=\"nofollow noopener\" target=\"_blank\">updates<\/a> from Build 28 that include fixes for various <a href=\"https:\/\/bugs.openjdk.org\/issues\/?jql=project%20%3D%20JDK%20AND%20fixversion%20%3D%2027%20and%20%22resolved%20in%20build%22%20%3D%20b29%20order%20by%20component%2C%20subcomponent\" rel=\"nofollow noopener\" target=\"_blank\">issues<\/a>. Further details on this release may be found in the <a href=\"https:\/\/jdk.java.net\/27\/release-notes\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n<p>JDK 28<\/p>\n<p><a href=\"https:\/\/github.com\/openjdk\/jdk\/releases\/tag\/jdk-28%2B5\" rel=\"nofollow noopener\" target=\"_blank\">Build 5<\/a> of the JDK 28 <a href=\"https:\/\/jdk.java.net\/28\/\" rel=\"nofollow noopener\" target=\"_blank\">early-access builds<\/a> was also made available this past week featuring <a href=\"https:\/\/github.com\/openjdk\/jdk\/compare\/jdk-28%2B4...jdk-28%2B5\" rel=\"nofollow noopener\" target=\"_blank\">updates<\/a> from Build 4 that include fixes for various <a href=\"https:\/\/bugs.openjdk.org\/issues\/?jql=project%20%3D%20JDK%20AND%20fixversion%20%3D%2028%20and%20%22resolved%20in%20build%22%20%3D%20b05%20order%20by%20component%2C%20subcomponent\" rel=\"nofollow noopener\" target=\"_blank\">issues<\/a>. More details on this release may be found in the <a href=\"https:\/\/jdk.java.net\/28\/release-notes\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n<p>GlassFish<\/p>\n<p>The release of <a href=\"https:\/\/glassfish.org\/\" rel=\"nofollow noopener\" target=\"_blank\">GlassFish<\/a> 7.1.1 delivers bug fixes, dependency upgrades and improvements such as: a streamline of the isValidAnnotation() method, defined in the <a href=\"https:\/\/github.com\/eclipse-ee4j\/glassfish\/blob\/main\/appserver\/web\/gf-weld-connector\/src\/main\/java\/org\/glassfish\/weld\/connector\/WeldUtils.java\" rel=\"nofollow noopener\" target=\"_blank\">WeldUtils<\/a> class, to fail-fast when there are no valid type names; and the isInterceptor() method, defined in the <a href=\"https:\/\/github.com\/eclipse-ee4j\/glassfish\/blob\/main\/appserver\/web\/weld-integration\/src\/main\/java\/org\/glassfish\/weld\/services\/InjectionServicesImpl.java\" rel=\"nofollow noopener\" target=\"_blank\">InjectionServicesImpl<\/a> class, is now cached to bypass the more expensive route of traversing the annotation-hierarchy on the CDI injection path on every request.<\/p>\n<p>This release also addresses four CVEs, two of which affect GlassFish versions 8.0.1, 8.0.0, 7.1.0 and 7.0.0-7.0.25:<\/p>\n<p>&#13;<br \/>\n\t<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-2586\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-2586<\/a>, a Remote Code Execution (RCE) vulnerability that allows an attacker with access to the Administration Console to send malicious crafted requests to execute arbitrary operating system commands with the privileges of the application service user.&#13;<br \/>\n\t<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-2587\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-2587<\/a>, also an RCE vulnerability in the server-side template rendering mechanism that allows an attacker to compromise the underlying host and enable capabilities such as reading\/modifying data, executing arbitrary commands, persistence, and lateral movement.&#13;<\/p>\n<p>Further details on this release may be found in the <a href=\"https:\/\/github.com\/eclipse-ee4j\/glassfish\/releases\/tag\/7.1.1\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n<p>GraalVM<\/p>\n<p>The <a href=\"https:\/\/medium.com\/graalvm\/graalvm-25-1-is-here-13829606982e\" rel=\"nofollow noopener\" target=\"_blank\">release<\/a> of <a href=\"https:\/\/www.graalvm.org\/\" rel=\"nofollow noopener\" target=\"_blank\">GraalVM<\/a> 25.1 ships with notable changes such as: a 3% reduction in the size of generated native images; support for using G1 GC in native images on macOS AArch64 (available only in Oracle GraalVM); and a total of 1500 libraries available in the <a href=\"https:\/\/github.com\/oracle\/graalvm-reachability-metadata\/blob\/master\/README.md\" rel=\"nofollow noopener\" target=\"_blank\">GraalVM Reachability Metadata Repository<\/a> for use by <a href=\"https:\/\/graalvm.github.io\/native-build-tools\/latest\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Native Build Tools<\/a>. More details on this release may be found in the <a href=\"https:\/\/www.graalvm.org\/release-notes\/25.1\/\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a> and this YouTube <a href=\"https:\/\/www.youtube.com\/watch?v=vmPscsMBqFc\" rel=\"nofollow noopener\" target=\"_blank\">video<\/a>.<\/p>\n<p>Micronaut<\/p>\n<p>The Micronaut Foundation has <a href=\"https:\/\/micronaut.io\/2026\/06\/30\/micronaut-framework-5-0-3-released\/\" rel=\"nofollow noopener\" target=\"_blank\">released<\/a> version 5.0.3 of the <a href=\"https:\/\/micronaut.io\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut Framework<\/a> based on <a href=\"https:\/\/github.com\/micronaut-projects\/micronaut-core\/releases\/tag\/v5.0.4\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut Core 5.0.4<\/a>, featuring patch updates to modules: <a href=\"https:\/\/micronaut-projects.github.io\/micronaut-aws\/latest\/guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut AWS<\/a>; <a href=\"https:\/\/micronaut-projects.github.io\/micronaut-data\/latest\/guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut Data<\/a>; <a href=\"https:\/\/micronaut-projects.github.io\/micronaut-sql\/latest\/guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut SQL Libraries<\/a>; <a href=\"https:\/\/micronaut-projects.github.io\/micronaut-r2dbc\/latest\/guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut R2DBC<\/a>; and <a href=\"https:\/\/micronaut-projects.github.io\/micronaut-problem-json\/latest\/guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut Problem JSON<\/a>; <a href=\"https:\/\/micronaut-projects.github.io\/micronaut-test\/latest\/guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut Test<\/a> and <a href=\"https:\/\/micronaut-projects.github.io\/micronaut-micrometer\/latest\/guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Micronaut Micrometer<\/a>. Further details on this release may be found in the <a href=\"https:\/\/github.com\/micronaut-projects\/micronaut-platform\/releases\/tag\/v5.0.3\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n<p>Open Liberty<\/p>\n<p>The <a href=\"https:\/\/openliberty.io\/blog\/2026\/06\/30\/26.0.0.7-beta.html\" rel=\"nofollow noopener\" target=\"_blank\">beta release<\/a> of <a href=\"https:\/\/openliberty.io\/\" rel=\"nofollow noopener\" target=\"_blank\">Open Liberty<\/a> 26.0.0.7 provides notable changes such as: support for <a href=\"https:\/\/jakarta.ee\/specifications\/data\/\" rel=\"nofollow noopener\" target=\"_blank\">Jakarta Data<\/a> 1.1-M3 featuring new capabilities that include stateful repositories, the new <a href=\"https:\/\/github.com\/jakartaee\/data\/blob\/main\/api\/src\/main\/java\/jakarta\/data\/repository\/First.java\" rel=\"nofollow noopener\" target=\"_blank\">@First<\/a> annotation, and the ability to use the ability to use the <a href=\"https:\/\/github.com\/jakartaee\/data\/blob\/main\/api\/src\/main\/java\/jakarta\/data\/restrict\/Restriction.java\" rel=\"nofollow noopener\" target=\"_blank\">Restriction<\/a> and <a href=\"https:\/\/github.com\/jakartaee\/data\/blob\/main\/api\/src\/main\/java\/jakarta\/data\/constraint\/Constraint.java\" rel=\"nofollow noopener\" target=\"_blank\">Constraint<\/a> interfaces as parameters in the <a href=\"https:\/\/github.com\/jakartaee\/data\/blob\/main\/api\/src\/main\/java\/jakarta\/data\/repository\/Find.java\" rel=\"nofollow noopener\" target=\"_blank\">@Find<\/a> and <a href=\"https:\/\/github.com\/jakartaee\/data\/blob\/main\/api\/src\/main\/java\/jakarta\/data\/repository\/Delete.java\" rel=\"nofollow noopener\" target=\"_blank\">@Delete<\/a> annotations; and the ability to disable the \/health endpoints from <a href=\"https:\/\/microprofile.io\/specifications\/health\/4-0\/\" rel=\"nofollow noopener\" target=\"_blank\">MicroProfile Health 4.0<\/a> when using a file-based health check mechanism.<\/p>\n<p>JReleaser<\/p>\n<p>The <a href=\"https:\/\/andresalmiray.com\/jreleaser-1-25-0-has-been-released\/\" rel=\"nofollow noopener\" target=\"_blank\">release<\/a> of <a href=\"https:\/\/jreleaser.org\/\" rel=\"nofollow noopener\" target=\"_blank\">JReleaser<\/a> 1.25.0 delivers bug fixes, documentation improvements, dependency upgrades and new features such as: support for multiple archive formats using jlink and native-image that can simultaneously generate ZIP and TAR files; and a change in masking secrets from all asterisks to displaying the first and last character of the secret. More details on this release may be found in the <a href=\"https:\/\/github.com\/jreleaser\/jreleaser\/releases\/tag\/v1.25.0\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n<p>Grails<\/p>\n<p>The second milestone release of <a href=\"https:\/\/grails.apache.org\/\" rel=\"nofollow noopener\" target=\"_blank\">Apache Grails<\/a> 8.0.0 ships with bug fixes, documentation improvements, dependency upgrades and notable changes such as: ensure that a Grails transformation fails (via the <a href=\"https:\/\/github.com\/apache\/grails-core\/blob\/8.0.x\/grails-core\/src\/main\/groovy\/org\/grails\/compiler\/injection\/GlobalGrailsClassInjectorTransformation.groovy\" rel=\"nofollow noopener\" target=\"_blank\">GlobalGrailsClassInjectorTransformation<\/a> class) if an incorrect directory is passed into a <a href=\"https:\/\/github.com\/apache\/grails-core\/blob\/8.0.x\/README.md\" rel=\"nofollow noopener\" target=\"_blank\">grails-core<\/a> build; and improved virtual thread cleanup and isolation of the thread-bound framework state when using instances of the Java <a href=\"https:\/\/docs.oracle.com\/en\/java\/javase\/25\/docs\/api\/java.base\/java\/lang\/ThreadLocal.html\" rel=\"nofollow noopener\" target=\"_blank\">ThreadLocal<\/a> class. Further details on this release may be found in the <a href=\"https:\/\/github.com\/apache\/grails-core\/releases\/tag\/v8.0.0-M2\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n<p>RefactorFirst<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/jimbethancourt\/\" rel=\"nofollow noopener\" target=\"_blank\">Jim Bethancourt<\/a>, Principal Software Consultant at <a href=\"https:\/\/improving.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Improving<\/a>, has released version 0.0.0 of <a href=\"https:\/\/github.com\/jimbethancourt\/RefactorFirst\/blob\/main\/README.md\" rel=\"nofollow noopener\" target=\"_blank\">RefactorFirst<\/a>, a utility that prioritizes the parts of an application that should be refactored. This release provides: an improvement calculating removal of a class relationship; the addition of object-oriented disharmony detectors as referenced from the book, &#8220;<a href=\"https:\/\/link.springer.com\/book\/10.1007\/3-540-39538-5\" rel=\"nofollow noopener\" target=\"_blank\">Object-Oriented Metrics in Practice<\/a>;&#8221; and a migration from <a href=\"https:\/\/d3js.org\/\" rel=\"nofollow noopener\" target=\"_blank\">D3<\/a> to <a href=\"https:\/\/vizdom.dev\/\" rel=\"nofollow noopener\" target=\"_blank\">Vizdom<\/a> for improved data visualization. More details on this release may be found in the <a href=\"https:\/\/github.com\/refactorfirst\/RefactorFirst\/releases\/tag\/0.9.0\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n<p>Java Operator SDK<\/p>\n<p>The <a href=\"https:\/\/javaoperatorsdk.io\/blog\/2026\/07\/02\/version-5.4-released\/\" rel=\"nofollow noopener\" target=\"_blank\">release<\/a> of <a href=\"https:\/\/javaoperatorsdk.io\/\" rel=\"nofollow noopener\" target=\"_blank\">Java Operator SDK<\/a> 5.4.0, a Kubernetes operator framework for Java, delivers notable changes such as: support for a shard selector, a Kubernetes-style label selector that is applied in addition to a normal label selector, to run multiple replicas; a new defaultFilters parameter added to the <a href=\"https:\/\/github.com\/operator-framework\/java-operator-sdk\/blob\/main\/operator-framework-core\/src\/main\/java\/io\/javaoperatorsdk\/operator\/api\/reconciler\/ControllerConfiguration.java\" rel=\"nofollow noopener\" target=\"_blank\">@ControllerConfiguration<\/a> annotation to provide an option to disable default filter events; and new getSecondaryResource() and getSecondaryResourcesAsStream() methods, added to the <a href=\"https:\/\/github.com\/operator-framework\/java-operator-sdk\/blob\/main\/operator-framework-core\/src\/main\/java\/io\/javaoperatorsdk\/operator\/api\/reconciler\/Context.java\" rel=\"nofollow noopener\" target=\"_blank\">Context<\/a> interface, to look up a single secondary resource directly by name. Further details on this release may be found in the <a href=\"https:\/\/github.com\/operator-framework\/java-operator-sdk\/milestone\/18?closed=1\" rel=\"nofollow noopener\" target=\"_blank\">release notes<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"This week&#8217;s Java roundup for June 29th, 2026, features news highlighting: a new JEP candidate, Strict Field Initialization;&hellip;\n","protected":false},"author":2,"featured_media":785051,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[11777,49,48,4113,155370,219282,39658,35858,277649,277650,155369,265562,202430,155366,175712,175714,202428,61],"class_list":["post-785050","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-architecture-design","tag-ca","tag-canada","tag-development","tag-glassfish","tag-graalvm","tag-grails","tag-java","tag-java-news-roundup-jun29-2026","tag-java-operator-sdk","tag-jdk-27","tag-jdk-28","tag-jreleaser","tag-micronaut","tag-open-jdk","tag-open-liberty","tag-refactorfirst","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/785050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=785050"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/785050\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/785051"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=785050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=785050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=785050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}