Harden 1.5.0 context boundaries and release checks - #210
Merged
Merged
Conversation
Harden parser-boundary encoding and EncodedWriter behavior, update compatibility and dependency metadata, and add release regression coverage.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
EncodedWriterclose, failure, flush, and slice-validation behaviorencoder-esapi; 1.4.1 is its final release and noencoder-esapi:1.5.0artifact will be publishedESAPI retirement
Version 1.5.0 publishes only
encoder,encoder-jsp, andencoder-jakarta-jsp(plus the parent POM). Historical Maven artifacts remain immutable. Existing adapter users must removeencoder-esapiand migrate Java Encoder-backed operations to the direct context APIs; ESAPI-only operations require a separately maintained implementation. The migration and support consequences are documented indocs/encoder-esapi-retirement.md.Dependabot cleanup
The default branch currently reports 233 alerts. Removing the ESAPI adapter eliminates the 39 adapter records, including every runtime-scoped alert. The remaining false or stale build-tool paths came from inactive plugin management, duplicated inherited closures, or older transitive plugin dependencies.
This change upgrades the active plugin closures, runs japicmp directly without its obsolete reporting wrapper, submits shared tooling once, and gives the optional Jakarta app its own executed-plugin allowlist. The five separately invoked compatibility fixtures inherit a local toolchain parent matching the submitted root downloader realm; their actual
copy-dependenciesexecution now loads BeanUtils 1.11.0, and a policy regression rejects child overrides. Fresh local library, Jakarta-app, and release-tool snapshots contain no ESAPI nodes and no versions matching the 233 retained alert records. No alert is dismissed or suppressed. GitHub can retire the absent records only after this is merged and the corrected dependency-submission workflow runs onmain.Compatibility
The three retained artifacts remain binary and source compatible with 1.4.1. General/block JavaScript and CDATA preserve parsed values but may emit different bytes and materially increase output size; XML-comment hyphens now become
~. Migration guidance and TLD documentation are included.Validation
2cb049cbde8eb80b3939e5b06fae67466762bce6pass, including Java 8 unit tests, Windows, CodeQL, and the required Docker/browser and aggregate gatesThe exact release-toolchain and reproducibility gates remain required on the maintainer-created release commit.
Release boundary
This keeps the project at
1.5.0-SNAPSHOT. Final versioning, publication date, release commit, reproducibility, signing, tagging, and publication remain separate maintainer-controlled release steps. There is no remaining ESAPI dependency-risk acceptance decision for the 1.5.0 artifact set because that artifact is not part of the release.