Prepare OWASP Java Encoder 1.5.0 release - #229
Merged
Merged
Conversation
Member
Author
|
I authorize the 1.5.0 release and have received Jeremy's verbal OK. His approval was verbal, not a GitHub PR review. All post-merge workflows have passed. No open issues, PRs, or Dependabot alerts remain at this check. The squash commit |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepares the three supported Java Encoder artifacts for the 1.5.0 security release. Sets the reactor and test-application dependency versions to 1.5.0, SCM tag to v1.5.0, and the reproducible source timestamp to the release commit's UTC timestamp. Updates release notes, migration guidance, dependency examples, and supported-version documentation. The retired encoder-esapi adapter is excluded.
Release source commit:
3fbc5da5bcdc49a6e2b4f39d3df7410b7c13d07d. Preserve this commit through a normal merge; do not squash or rebase it.Validation is complete on this exact commit:
107b0e4e1f459087d6bbd1e37222c05c7c4630fa55d52bc1e7c99c0077897590.This is release preparation, not publication. Required independent maintainer approval and a normal merge remain. The release tag must identify the exact source commit above, not the merge commit. Central publication, verification of downloaded artifacts, the signed tag, advisory publication, and the GitHub release remain outstanding. Availability notices deliberately remain pending until the published artifacts are independently verified.