Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/CI_SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,10 +67,10 @@ for child or fixture POMs. Graph reports and submission JSON are retained for
inspection. Inspect representative Jakarta Spring/Tomcat dependencies in the
resulting graph; alert counts are not gates.

The immutable 1.4.1 Java Encoder artifacts used by japicmp are intentional
The immutable 1.5.0 Java Encoder artifacts used by japicmp are intentional
development-only comparison inputs. Keep them visible in the build graph: an alert
on a baseline artifact describes that historical input, not a dependency shipped
to 1.5 consumers, and must be assessed rather than hidden with a graph filter.
to current development consumers, and must be assessed rather than hidden with a graph filter.

All submissions use detector `encoder-maven-build-graph` with distinct, stable
correlators. Keep the action's detector inputs synchronized with the
Expand Down
30 changes: 27 additions & 3 deletions .github/DEPENDENCY_DECISIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ old **OSGi framework** compatibility fixture.

Use `javax.servlet.jsp-api` **2.3.3** as the published `encoder-jsp` provided
dependency. Keep JSP 2.2.1, Servlet 3.0.1 and EL 2.2.5 as the independent minimum
consumer fixture. Japicmp resolves 1.4.1 against the old support API and the 1.5
consumer fixture. For the 1.5.0 release, japicmp resolved 1.4.1 against the old support API and the 1.5
artifact against the new one, so inherited API changes are not hidden. The Java 8,
JPMS, OSGi and packaged Jasper checks continue to exercise the original artifacts.
This is a consumer-POM dependency change, not a claim that the minimum supported
Expand All @@ -36,8 +36,32 @@ classpath. Their test-scope declarations remain visible in the published source
POM, but Maven does not propagate them into ordinary consumer dependency graphs
and their classes do not enter the adapter JAR. Keep the independent Java 8
packaged-consumer fixture on Jakarta Pages 3.0.0, Servlet 5.0.0 and EL 4.0.0. The
old Servlet 6.0.0 and EL 4.0.0 support JARs remain explicit japicmp inputs for the
1.4.1 side of the comparison; the new side uses the new test APIs.
old Servlet 6.0.0 and EL 4.0.0 support JARs were explicit japicmp inputs for the
1.4.1 side of the release comparison; the new side used the new test APIs.

After publication, `1.5.1-SNAPSHOT` compares against the immutable 1.5.0 artifacts.
Its old support classpaths therefore use JSP 2.3.3, Jakarta Servlet 6.1.0 and
EL 6.0.1, matching that release. This does not change the independent minimum
consumer fixtures or the published provided dependencies.

## Post-release Jackson build-plugin fix — 2026-09-28

GitHub's Dependabot alerts for
[GHSA-q4xh-88c3-wmh7](https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7)
and [GHSA-wjgm-6hv5-3cvf](https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf)
surfaced after 1.5.0 publication. Both advisories identify Jackson 3.1.6 as the fixed 3.1 release.
The unpublished Jakarta fixture's executed `spring-boot-maven-plugin:4.1.1`
depends on `spring-boot-buildpack-platform:4.1.1`, which brings in Jackson
databind/core 3.1.5. Pin both to **3.1.6** directly in that plugin's dependencies.
Application dependency management does not control Maven plugin realms.

The resolved fixture compile/runtime/test tree has no Jackson databind; its
existing JSP-only web starter excludes the JSON starter. Jackson annotations
remain test-only via Testcontainers. The core library's independent test-only
Jackson 2.22.3 is outside the two affected 2.x ranges. No application exclusion,
security suppression or published library dependency is added or changed.
Verify both the resolved plugin closure and the packaged browser fixture in CI;
a source-POM pin alone does not demonstrate the executed dependency version.

## Deferred proposals and reconsideration conditions

Expand Down
11 changes: 9 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,11 +4,18 @@ Released entries are grounded in the linked immutable tags, GitHub release notes
and retained README announcements. Dates below are GitHub publication dates in
UTC where a release record exists; older announcement/tag dates are labeled.
An open proposal is not a release. Historical tags, assets and signatures remain
unchanged. [1.4.1 is also available from Central](releases/1.4.1-central-publication.md).
unchanged. [1.5.0 is available from Central](releases/1.5.0-central-publication.md).

## Unreleased

No changes are recorded after 1.5.0 yet.
- Resume development at `1.5.1-SNAPSHOT`, with the immutable 1.5.0 public-API
baseline and its matching support APIs. Minimum-consumer fixtures are unchanged.
- Discover release tags independently of commit ancestry so squash merges cannot
leave the compatibility baseline stale; add isolated Git regressions.
- Record verified 1.5.0 publication and replace pending-availability notices.
- Update Jackson core/databind to 3.1.6 in the unpublished Jakarta fixture's
Spring Boot Maven plugin realm for GHSA-q4xh-88c3-wmh7 and GHSA-wjgm-6hv5-3cvf.
Published library dependencies and release artifacts are unchanged.

## 1.5.0 — 2026-09-28 UTC

Expand Down
20 changes: 12 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,16 +9,17 @@ has no runtime dependencies; optional JSP and Jakarta adapters provide view-laye
bindings. Encoding is one part of [XSS prevention][xss], alongside
safe templates, URL validation and other application controls.

**Release preparation:** version 1.5.0 fixes parser-boundary vulnerabilities in
**Released 2026-09-28:** version 1.5.0 fixes parser-boundary vulnerabilities in
JavaScript-in-HTML, CDATA, and XML-comment fragment composition. Versions through
1.4.1 do not contain those fixes. The signed 1.5.0 artifacts are not available
until the maintainers complete the release gates and update this notice with the
verified GitHub and Maven Central links. See the [1.5.0 release notes](releases/1.5.0.md)
1.4.1 do not contain those fixes. The [signed GitHub release][release] and
[Maven Central artifacts](releases/1.5.0-central-publication.md) have been
independently verified. See the [1.5.0 release notes](releases/1.5.0.md),
[security advisory](https://github.com/OWASP/owasp-java-encoder/security/advisories/GHSA-g8p6-7r8f-qrpv)
and [VERIFYING.md](VERIFYING.md).

## Start using the OWASP Java Encoders

After 1.5.0 publication is independently verified, select the dependency you need.
Select the dependency you need.
The three supported artifacts use group ID `org.owasp.encoder`:

| Artifact ID | Purpose and runtime dependencies |
Expand All @@ -39,12 +40,15 @@ Replace `encoder` with one tag adapter artifact ID when needed; each adapter bri
in core. Keep separately managed core/adapter versions aligned. Use **one** of the
javax or Jakarta taglib JARs: they share `org.owasp.encoder.tag` and must not coexist
on the same classpath or module path. See the [runtime matrix](compatibility/README.md) and
[dependency/license inventory](docs/dependencies.md). Do not use the example version
until its signed artifacts and Central availability have been verified.
[dependency/license inventory](docs/dependencies.md).

`encoder-esapi` was retired after 1.4.1 and will not be published or supported in
`encoder-esapi` was retired after 1.4.1 and is not included or supported in
1.5.0. Applications using it must [migrate away from the adapter](docs/encoder-esapi-retirement.md).

Published 1.5.0 API documentation: [core](https://javadoc.io/doc/org.owasp.encoder/encoder/1.5.0/),
[javax JSP](https://javadoc.io/doc/org.owasp.encoder/encoder-jsp/1.5.0/) and
[Jakarta JSP](https://javadoc.io/doc/org.owasp.encoder/encoder-jakarta-jsp/1.5.0/).

```java
import org.owasp.encoder.Encode;

Expand Down
22 changes: 13 additions & 9 deletions RELEASING.md
Original file line number Diff line number Diff line change
@@ -1,23 +1,23 @@
# Releasing OWASP Java Encoder

## Release gate for 1.5
## Release gate

Do not tag, publish, or announce a 1.5 release until **all open issues and all
Do not tag, publish, or announce a release until **all open issues and all
open pull requests have been handled**. Before considering release approval,
inventory the full open backlog and record the outcome and supporting review
or verification for every item. Completing a maintenance batch does not satisfy
this gate on its own. Keep 1.5 development at `1.5.0-SNAPSHOT` until maintainers
this gate on its own. Keep current development at `1.5.1-SNAPSHOT` until maintainers
deliberately create the exact release commit after the technical gates pass.
Changing that commit to `1.5.0` is release preparation, not release approval.
Changing that commit to a release version is release preparation, not release approval.

The [2026-09-26 maintenance closeout](releases/maintenance-closeout.md) records
the final backlog inventory and dispositions for #110 and #169. A closed tracker
does not waive this gate: repeat the complete open-issue/PR inventory when a 1.5
does not waive this gate: repeat the complete open-issue/PR inventory when a new
release is actually proposed and obtain release approval then.

The signed 1.4.1 release has been [published to Central and verified](releases/1.4.1-central-publication.md).
That publication is separate from the 1.5 release gate. Do not rebuild or replace
1.4.1 artifacts, republish its coordinates, or move its tag.
The signed 1.5.0 release has been [published to Central and verified](releases/1.5.0-central-publication.md).
Repeat these gates for each subsequent release. Do not rebuild or replace
published artifacts, republish existing coordinates, or move release tags.

## Publishing access and project identity

Expand Down Expand Up @@ -158,7 +158,11 @@ uploading. Keep an audit record of the exact uploaded bundle and its SHA-256.
that has not actually published.
5. Set main to the next unreleased version (for example `1.5.1-SNAPSHOT` or
`1.6.0-SNAPSHOT`, chosen through version review), update `jakarta-test`
accordingly, and reset the SCM tag to `HEAD`. README examples and the
accordingly, and reset the SCM tag to `HEAD`. Advance `public.api.baseline.version`
and its old support-API classpaths to the newly published immutable release.
Fetch all release tags before running the baseline regression: the tested
release commit can be outside main's ancestry after a squash merge.
README examples and the
supported-version table continue to refer to the published release.
6. Verify GitHub CI on main, update the OWASP project page, and check javadoc.io
after its indexing delay.
Expand Down
13 changes: 9 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,11 @@

## Supported Versions

Version **1.5.0** is the prepared security release. Do not treat it as available
until the signed GitHub artifacts and Maven Central publication have been
independently verified and this paragraph is updated with the exact links and date.
Version **1.5.0**, published **2026-09-28 UTC**, is the current security release.
The [signed GitHub assets](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.5.0)
and [Maven Central publication](releases/1.5.0-central-publication.md) have been
independently verified. See [GHSA-g8p6-7r8f-qrpv](https://github.com/OWASP/owasp-java-encoder/security/advisories/GHSA-g8p6-7r8f-qrpv)
for affected versions and migration guidance.

Only the latest 1.x release receives security fixes. Fixes ship in a new release;
older release lines are not patched.
Expand Down Expand Up @@ -85,11 +87,14 @@ release tag, then verify:
```sh
gpg --import KEYS
gpg --verify encoder-1.5.0.jar.asc encoder-1.5.0.jar
gpg --verify SHA256SUMS.asc SHA256SUMS
gpg --verify SHA512SUMS.asc SHA512SUMS
shasum -a 256 -c SHA256SUMS
shasum -a 512 -c SHA512SUMS
```

The `SHA256SUMS` and `SHA512SUMS` manifests are included with the GitHub release
For full-fingerprint checks in a fresh public-only keyring, follow
[VERIFYING.md](VERIFYING.md). The `SHA256SUMS` and `SHA512SUMS` manifests are included with the GitHub release
assets. Maven Central provides individual checksum files alongside each artifact.
A new project key and its fingerprint must be added to `KEYS` before a release
uses it. Previously published artifacts retain their original signatures.
10 changes: 5 additions & 5 deletions VERIFYING.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,14 @@ identity authority. Obtain [KEYS](KEYS) from a trusted project revision and chec
the fingerprint before use. Never import private key material to verify a release.

For 1.4.1 and later releases until a documented rotation, the expected project key
is `1C5F632B86809F2F5DB25092BEA0075F94074A9B`. The [1.4.1 release instructions](releases/1.4.1.md#verification)
cover its signed GitHub assets. The [Central publication verification](releases/1.4.1-central-publication.md)
is `1C5F632B86809F2F5DB25092BEA0075F94074A9B`. The [1.5.0 release record](releases/1.5.0.md#verification-and-evidence)
covers its signed GitHub assets. The [Central publication verification](releases/1.5.0-central-publication.md)
confirms that Central serves the same artifacts and signatures.

## Fresh public-only keyring

Download the artifact, its original `.asc`, and the trusted `KEYS`. This example
verifies the published 1.4.1 release. For historical releases, use the full
verifies the published 1.5.0 release. For historical releases, use the full
fingerprint mapped below and review the historical key's expiry and algorithms.
Commands use GnuPG and `shasum` (or equivalent SHA tools).

Expand All @@ -22,7 +22,7 @@ verify_home=$(mktemp -d)
chmod 700 "$verify_home"
gpg --homedir "$verify_home" --batch --no-autostart --import KEYS
expected_fingerprint=1C5F632B86809F2F5DB25092BEA0075F94074A9B
artifact=encoder-1.4.1.jar
artifact=encoder-1.5.0.jar
gpg --homedir "$verify_home" --no-autostart --fingerprint "$expected_fingerprint"
gpg --homedir "$verify_home" --batch --no-autostart --status-fd 1 \
--verify "$artifact.asc" "$artifact" > signature.status || exit 1
Expand All @@ -45,7 +45,7 @@ A Maven `.sha256` sidecar usually contains **only a hex digest**, not a filename
After fetching it over the intended distribution channel, form a check manifest:

```sh
artifact=encoder-1.4.1.jar
artifact=encoder-1.5.0.jar
expected_hash=$(tr -d '[:space:]' < "$artifact.sha256")
printf '%s\n' "$expected_hash" | grep -Eq '^[[:xdigit:]]{64}$' || exit 1
printf '%s %s\n' "$expected_hash" "$artifact" | shasum -a 256 --check || exit 1
Expand Down
10 changes: 7 additions & 3 deletions compatibility/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,8 +84,12 @@ fail these guards.
During ordinary `./mvnw verify`, Animal Sniffer checks each library against the Java 8
API signature. This catches linkage such as Java 9's covariant `CharBuffer.flip()`
even when bytecode still has class version 52. japicmp checks public/protected API
binary and source compatibility against **1.4.1**, the immutable release immediately
preceding 1.5.0. Update the pinned baseline for the next development version. Missing
binary and source compatibility against **1.5.0** during **1.5.1-SNAPSHOT**
development. The baseline guard selects the latest preceding semantic release tag,
including signed source commits integrated by squash merge; fetch all release tags
before running it. The old support classpath matches the 1.5.0 POMs (JSP 2.3.3,
Jakarta Servlet 6.1.0 and EL 6.0.1). Independent minimum-consumer fixtures remain
unchanged. Update these pins together after each release. Missing
types are not broadly ignored: dependencies are resolved so inherited API changes
remain visible. Both checks run in existing `build.yaml` jobs because those jobs
reach the `verify` phase.
Expand Down Expand Up @@ -135,7 +139,7 @@ multi-release layout remain unchanged.

## Published identities and development import ranges

The tables below describe the prepared **1.5.0** artifacts. The names are
The tables below describe the published **1.5.0** artifacts. The names are
historical identities preserved in 1.x; the OSGi import floors reflect the new
1.5 calls and must not be projected onto older published JARs.

Expand Down
2 changes: 1 addition & 1 deletion core/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@
<parent>
<groupId>org.owasp.encoder</groupId>
<artifactId>encoder-parent</artifactId>
<version>1.5.0</version>
<version>1.5.1-SNAPSHOT</version>
</parent>

<artifactId>encoder</artifactId>
Expand Down
5 changes: 2 additions & 3 deletions docs/contexts.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
# Output contexts and boundaries

This guide describes version **1.5.0**; feature introductions are marked below.
Do not treat that version as available until the [release-preparation notice](../README.md)
is updated with independently verified signed artifacts and Maven Central links.
This guide describes the published version **1.5.0**; feature introductions are
marked below. See the [verified downloads](../releases/1.5.0-central-publication.md).
The [Encode Javadoc source](../core/src/main/java/org/owasp/encoder/Encode.java) is
the detailed per-method contract; each method has a String-returning and a
`(Writer out, String input)` overload. `Encoders` exposes shared stateless encoders;
Expand Down
5 changes: 3 additions & 2 deletions docs/dependencies.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,9 @@ unsupported; see the [retirement and migration notice](encoder-esapi-retirement.
## Consumer dependency inventory — 2026-09-27

Generated from dependency-plugin 3.11.0's resolved reactor `dependency:tree`
JSON for the reviewed `1.5.0-SNAPSHOT` candidate. Release preparation does not
change the published dependency graph. This inventory includes the publishable
JSON for the reviewed `1.5.0-SNAPSHOT` candidate. The published 1.5.0 POMs retain
this consumer graph; see the [publication record](../releases/1.5.0-central-publication.md).
This inventory includes the publishable
modules' compile/runtime and provided scopes, excludes test/plugin dependencies
and this project's own BSD-3-Clause modules, and identifies the consuming module.

Expand Down
7 changes: 3 additions & 4 deletions docs/usage.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,8 @@
# Java and JSP examples

These examples target version **1.5.0**. Do not use that coordinate until the
[release-preparation notice](../README.md) is updated with independently verified
signed artifacts and Maven Central links. Features marked **1.5** are new in this
release.
These examples target the published version **1.5.0**. See the
[verified downloads](../releases/1.5.0-central-publication.md).
Features marked **1.5** are new in this release.

## HTML and Writer output

Expand Down
6 changes: 5 additions & 1 deletion jakarta-test/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -26,9 +26,11 @@
<tomcat.version>11.0.26</tomcat.version>
<!-- Keep the client aligned with the reviewed, digest-pinned browser image. -->
<selenium.version>4.49.0</selenium.version>
<!-- GHSA-q4xh-88c3-wmh7 / GHSA-wjgm-6hv5-3cvf: Boot's separate plugin realm. -->
<jackson.build.version>3.1.6</jackson.build.version>
<!-- Must equal the version in the root pom.xml so this app tests the
encoder-jakarta-jsp built in the same reactor. CI checks this. -->
<encoder.version>1.5.0</encoder.version>
<encoder.version>1.5.1-SNAPSHOT</encoder.version>
</properties>
<dependencies>
<dependency>
Expand Down Expand Up @@ -206,6 +208,8 @@
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-maven-plugin</artifactId>
<dependencies>
<dependency><groupId>tools.jackson.core</groupId><artifactId>jackson-databind</artifactId><version>${jackson.build.version}</version></dependency>
<dependency><groupId>tools.jackson.core</groupId><artifactId>jackson-core</artifactId><version>${jackson.build.version}</version></dependency>
<dependency><groupId>org.apache.commons</groupId><artifactId>commons-lang3</artifactId><version>3.20.0</version></dependency>
<dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>3.6.2</version></dependency>
</dependencies>
Expand Down
Loading
Loading