Skip to content

Prepare OWASP Java Encoder 1.5.0 release - #229

Merged
jmanico merged 1 commit into
mainfrom
release/1.5.0-preparation
Sep 28, 2026
Merged

jmanico merged 1 commit into
mainfrom
release/1.5.0-preparation

Conversation

@jmanico

@jmanico jmanico commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Prepares the three supported Java Encoder artifacts for the 1.5.0 security release. Sets the reactor and test-application dependency versions to 1.5.0, SCM tag to v1.5.0, and the reproducible source timestamp to the release commit's UTC timestamp. Updates release notes, migration guidance, dependency examples, and supported-version documentation. The retired encoder-esapi adapter is excluded.

Release source commit: 3fbc5da5bcdc49a6e2b4f39d3df7410b7c13d07d. Preserve this commit through a normal merge; do not squash or rebase it.

Validation is complete on this exact commit:

  • All 18 GitHub checks passed, including Docker/browser tests, Java 8–25 packaged consumers, Linux/Windows wrapper checks, and CodeQL.
  • A clean local reactor verification passed 2,287 tests with no failures, errors, or skips using Eclipse Temurin 17.0.20.1+1 and Maven wrapper 3.9.16. The build used private Java/Maven homes, empty Maven settings, UTF-8, UTC, and externally blocked networking with loopback allowed.
  • Coverage, Checkstyle, Java 8 API signatures, public API comparison against 1.4.1, JPMS/OSGi, packaged Tomcat/TLD checks, and effective-POM SCM checks passed. Local packaged consumers also passed on Java 11, 17, 21, and 25.
  • All 13 release payload files match two fresh source-export builds byte for byte. Build permissions were normalized before the final comparison.
  • The retained payloads and two checksum manifests are signed and independently verified against the project release key. The local Central bundle contains the expected 78 entries. Its SHA-256 is 107b0e4e1f459087d6bbd1e37222c05c7c4630fa55d52bc1e7c99c0077897590.

This is release preparation, not publication. Required independent maintainer approval and a normal merge remain. The release tag must identify the exact source commit above, not the merge commit. Central publication, verification of downloaded artifacts, the signed tag, advisory publication, and the GitHub release remain outstanding. Availability notices deliberately remain pending until the published artifacts are independently verified.

@jmanico
jmanico requested a review from jeremylong as a code owner September 28, 2026 18:50
@jmanico
jmanico merged commit 030c137 into main Sep 28, 2026
18 checks passed
@jmanico

jmanico commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

I authorize the 1.5.0 release and have received Jeremy's verbal OK. His approval was verbal, not a GitHub PR review.

All post-merge workflows have passed. No open issues, PRs, or Dependabot alerts remain at this check.

The squash commit 030c137fc14f277afc5fbe303d2ca8a149f8068b and tested release commit 3fbc5da5bcdc49a6e2b4f39d3df7410b7c13d07d have identical file trees. The retained signed bundle remains tied to the tested commit, which will be the release-tag target. Central publication and verification are still pending.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant