spring-boot-api-versioning

A set of rules for managing different versions of a Spring Boot REST API, the web interface used by programs to communicate with it. It defines URL formats, compatible changes, and when a new version is required.

In plain words
What is it for?
Use it when adding or changing API endpoints, request fields, response fields, or HTTP methods. It helps decide whether a change can stay in the current version or needs a new one.
Why use it?
It prevents client programs from breaking when the API changes. It also gives developers one consistent way to announce and retire versions.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/lsampaioweb/ai-instructions/spring-boot-api-versioning
Clone the repo
git clone --depth 1 https://github.com/lsampaioweb/ai-instructions

Made for: Cursor.

Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 554 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00554
Opus 5 $0.00000 $0.00277
Sonnet 5 $0.00000 $0.00111
Haiku 4.5 $0.00000 $0.00055

Measured 2d ago against content hash 4533ab5cc52b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

spring-boot-api-versioning scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/spring-boot-api-versioning.mdc · 36 lines

How it starts

The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Spring Boot API-Versioning Engine

Rules

  • Use URL path versioning with an explicit /api/v1 prefix for all REST endpoints.
  • Use integer version numbers in the format /api/vN (e.g., /api/v1, /api/v2).
  • Do not use floating-point or date-based version identifiers such as /api/v1.1 or /api/2024-01.
  • Exclude MVC page controllers and view routes from API version-prefix enforcement.
  • Use one canonical versioning strategy across the entire project.
  • Declare version changes explicitly in controller route mappings.
  • Declare a shared base-path constant at the controller class level when the versioned route is reused across methods.
  • Keep v1 changes additive and backward compatible.
  • Treat these changes as additive and backward compatible: adding optional request fields with defaults, adding new response fields, and adding new endpoints.
  • Create a new API version for every breaking contract change.
  • Treat these changes as breaking: removing or renaming a field, changing a field type, making an optional field required, removing an endpoint, changing an endpoint path, or changing an HTTP method.
  • Keep request and response DTO changes backward compatible within the same version.
  • Use version-specific DTO suffixes when payload contracts diverge across versions (e.g., HolidayV1Response, HolidayV2Response).
  • Share the same DTO across versions only when the payload contract is identical.
  • Keep route versioning distinct from OpenAPI document version metadata.
  • Keep controller tests aligned with the active versioned route prefix.
  • When v2 or later is introduced, keep old and new versions available side by side until the old version is explicitly deprecated.
  • When v2 or later is introduced, document migration notes and client impact.
  • Announce a deprecated API version via a Deprecation response header per RFC 8594.
  • Announce a deprecated API version via a Sunset response header per RFC 8594.
  • Always set both Deprecation and Sunset headers together when a version is scheduled for removal.
  • Maintain a deprecated API version for at least one full release cycle after the deprecation announcement; remove a version only in a later release than the one that deprecates it.

Read the full file on GitHub · 36 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 36 lines · 0 tokens per session scan A 4533ab5cc52b

Subscribe to this mod's changes

spring-boot-api-versioning is a cursor rule published in the GitHub repository lsampaioweb/ai-instructions (1 stars, last pushed 10d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 554 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.