Skip to content

Harden 1.5.0 context boundaries and release checks - #210

Merged
jmanico merged 7 commits into
mainfrom
fix/1.5.0-release-review
Sep 28, 2026
Merged

jmanico merged 7 commits into
mainfrom
fix/1.5.0-release-review

Conversation

@jmanico

@jmanico jmanico commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Summary

  • harden fragment-boundary containment for HTML script JavaScript, CDATA, and XML comments across String, Writer, streaming, JSP, and Jakarta paths
  • fix EncodedWriter close, failure, flush, and slice-validation behavior
  • compare the three published APIs against 1.4.1 and correct effective child SCM metadata
  • retire and remove encoder-esapi; 1.4.1 is its final release and no encoder-esapi:1.5.0 artifact will be published
  • remove advisory-affected dependencies from active Maven plugin realms and correct GitHub dependency submission so it reports only executed build tooling
  • add parser, streaming, packaged-consumer, dependency-graph, and release-policy regressions

ESAPI retirement

Version 1.5.0 publishes only encoder, encoder-jsp, and encoder-jakarta-jsp (plus the parent POM). Historical Maven artifacts remain immutable. Existing adapter users must remove encoder-esapi and migrate Java Encoder-backed operations to the direct context APIs; ESAPI-only operations require a separately maintained implementation. The migration and support consequences are documented in docs/encoder-esapi-retirement.md.

Dependabot cleanup

The default branch currently reports 233 alerts. Removing the ESAPI adapter eliminates the 39 adapter records, including every runtime-scoped alert. The remaining false or stale build-tool paths came from inactive plugin management, duplicated inherited closures, or older transitive plugin dependencies.

This change upgrades the active plugin closures, runs japicmp directly without its obsolete reporting wrapper, submits shared tooling once, and gives the optional Jakarta app its own executed-plugin allowlist. The five separately invoked compatibility fixtures inherit a local toolchain parent matching the submitted root downloader realm; their actual copy-dependencies execution now loads BeanUtils 1.11.0, and a policy regression rejects child overrides. Fresh local library, Jakarta-app, and release-tool snapshots contain no ESAPI nodes and no versions matching the 233 retained alert records. No alert is dismissed or suppressed. GitHub can retire the absent records only after this is merged and the corrected dependency-submission workflow runs on main.

Compatibility

The three retained artifacts remain binary and source compatible with 1.4.1. General/block JavaScript and CDATA preserve parsed values but may emit different bytes and materially increase output size; XML-comment hyphens now become ~. Migration guidance and TLD documentation are included.

Validation

  • isolated clean reactor: 2,287 tests, 0 failures/errors/skips; coverage, Checkstyle, Animal Sniffer, japicmp, JPMS, OSGi, TLD, and packaged Tomcat checks passed
  • streaming campaign: 655,446 checks across 22 contexts
  • Chrome, jsoup, JAXP, Node JavaScript/JSON, and Java compiler oracles passed with raw negative controls
  • packaged classpath, JPMS, and OSGi consumers passed for all three artifacts on Java 8, 11, 17, 21, and 25
  • release/script tests: 26 passed; packaged-artifact guards: 17 passed
  • effective SCM POM checks, optional Jakarta WAR packaging, and normal/Jakarta/release dependency graphs passed
  • all 18 checks returned for exact head 2cb049cbde8eb80b3939e5b06fae67466762bce6 pass, including Java 8 unit tests, Windows, CodeQL, and the required Docker/browser and aggregate gates

The exact release-toolchain and reproducibility gates remain required on the maintainer-created release commit.

Release boundary

This keeps the project at 1.5.0-SNAPSHOT. Final versioning, publication date, release commit, reproducibility, signing, tagging, and publication remain separate maintainer-controlled release steps. There is no remaining ESAPI dependency-risk acceptance decision for the 1.5.0 artifact set because that artifact is not part of the release.

  • Change is scoped and relevant historical records/notices are preserved.
  • Documentation, changelog, migration notes, and tests cover behavior changes.
  • No credentials or private review evidence are included.

Harden parser-boundary encoding and EncodedWriter behavior, update compatibility and dependency metadata, and add release regression coverage.
@jmanico
jmanico requested a review from jeremylong as a code owner September 27, 2026 21:48
@jmanico
jmanico merged commit f25c771 into main Sep 28, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant