Skip to content

Bump owasp.encoder.version from 1.4.1 to 1.5.0 - #392

Merged
dschadow merged 1 commit into
mainfrom
dependabot/maven/owasp.encoder.version-1.5.0
Oct 2, 2026
Merged

dschadow merged 1 commit into
mainfrom
dependabot/maven/owasp.encoder.version-1.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps owasp.encoder.version from 1.4.1 to 1.5.0.
Updates org.owasp.encoder:encoder from 1.4.1 to 1.5.0

Release notes

Sourced from org.owasp.encoder:encoder's releases.

OWASP Java Encoder 1.5.0

Version 1.5.0 is available from Maven Central. All nine binary/source/Javadoc JARs, four POMs, and their thirteen signatures were downloaded from Central and verified against the retained signed release files. There is no encoder-esapi:1.5.0 release.

Security and correctness

  • Fixes encoded fragments completing outer HTML or XML parser delimiters across trusted-text boundaries in JavaScript HTML/block, CDATA, and XML-comment contexts. Versions through 1.4.1 are affected. See GHSA-g8p6-7r8f-qrpv.
  • Fixes EncodedWriter close/finalization behavior, exception handling, and overflow-safe array-slice validation.
  • Adds JSON encoding APIs and matching JSP/Jakarta tags and EL functions, plus XML 1.1 bindings.

Compatibility and migration

Public Java APIs remain binary and source compatible with 1.4.1 for the three supported libraries. Java 8 remains the minimum runtime; packaged consumers passed on Java 8, 11, 17, 21, and 25.

The security fixes deliberately change some encoded output:

  • JavaScript HTML/block modes emit additional hexadecimal escapes while preserving the string value. Review byte snapshots, cache keys, signatures, and output-size budgets.
  • CDATA preserves parsed text but can expand to 13 output characters per input character and can change parser event boundaries.
  • XML-comment hyphens become ~ under the documented lossy policy.

The optional ESAPI adapter is retired. Version 1.4.1 is its final published release and is unsupported; migrate to direct Java Encoder APIs. Mixing the 1.4.1 adapter with the 1.5 core is not a supported migration.

See the migration notes, ESAPI retirement guide, and changelog.

Maven artifacts

Use group org.owasp.encoder and version 1.5.0:

The optional test WAR and retired ESAPI adapter are not published.

Verification

Exact release source: 3fbc5da5bcdc49a6e2b4f39d3df7410b7c13d07d. The signed v1.5.0 tag identifies this tested commit. PR #229's squash commit 030c137fc14f277afc5fbe303d2ca8a149f8068b has the identical file tree.

Release artifacts were built with Eclipse Temurin 17.0.20.1+1 and the committed Maven 3.9.16 wrapper. All 2,287 local reactor tests passed with zero failures, errors, or skips. All thirteen unsigned payload files matched two fresh source-export builds. Post-merge Java CI, packaged consumers, and CodeQL passed, including the browser and Java 8 gates.

Project signing fingerprint: 1C5F632B86809F2F5DB25092BEA0075F94074A9B.

The assets contain the public KEYS, detached signatures, and signed SHA-256/SHA-512 manifests. Follow the verification instructions, using this full expected fingerprint and the 1.5.0 filenames. Authenticate each checksum manifest's signature before checking its entries.

Central bundle SHA-256: 107b0e4e1f459087d6bbd1e37222c05c7c4630fa55d52bc1e7c99c0077897590.

The source-tag documentation preserves the pre-publication notices from the immutable release commit. This release record confirms the subsequently verified Central publication; publication follow-up documentation belongs in a later commit, not a rebuilt release.

Changelog

Sourced from org.owasp.encoder:encoder's changelog.

1.5.0 — 2026-09-28 UTC

This is a security release for GHSA-g8p6-7r8f-qrpv. Signed artifact availability and independent verification are tracked in the 1.5.0 release record.

  • build: stop Dependabot from recreating already-reviewed incompatible API, servlet-engine and build-tool version proposals. The ignores are limited to routine version updates in the rejected SemVer classes; security updates remain eligible. Mixed historical/current coordinates require manual version review because Dependabot classifies them from their lowest occurrence.
  • removed: retire the optional encoder-esapi adapter. Version 1.4.1 is its final published release and is no longer supported; no encoder-esapi:1.5.0 artifact will be published. Consumers must remove the adapter and migrate Java Encoder-backed calls to the direct context APIs. Historical Maven artifacts remain immutable.
  • build: remove advisory-affected dependencies from active Maven plugin realms, including the separately invoked compatibility-fixture downloader; invoke the same japicmp engine without its obsolete reporting wrapper; and submit only actually invoked build plugins to GitHub's dependency graph. Shared inherited tooling is recorded once, and no Dependabot alert is dismissed or suppressed.
  • build/compatibility: update the published JSP provided API to 2.3.3 and the Jakarta test classpath to Servlet 6.1.0 and EL 6.0.1, while retaining independent JSP 2.2.1 and Java 8-compatible Jakarta minimum-consumer fixtures. Japicmp now resolves distinct old/new support classpaths so the 1.4.1 comparison remains complete. Dependabot scans the root Maven reactor once, rather than opening duplicate module proposals, and continues to scan the standalone compatibility-fixture project separately.
  • feat: all four forJavaScript* methods encode dollar sign ($) as \x24, backtick as \x60, and opening brace ({) as \x7b #129. Escaping { prevents input after a trusted $ from completing ${...}. Encoded output now supports literal text in ordinary (untagged) template literals as well as single- and double-quoted strings. This changes the encoded output while preserving its decoded JavaScript string value. Tagged templates (including String.raw), ${...} expression bodies, JSON, and script URLs are unsupported; each method's HTML context restrictions still apply.
  • fix: all four forJavaScript* methods escape unpaired UTF-16 surrogates as \uXXXX, preserving their JavaScript string values through UTF-8 serialization #135, and escape DEL/C1 controls (U+007F to U+009F) as \xNN #163. Valid surrogate pairs and other non-ASCII text remain unescaped except U+2028/U+2029. These are output-fidelity changes; NEL was already ordinary JavaScript string data.
  • fix: the HTML/block JavaScript encoders escape every ASCII character that can contribute to a case-insensitive </script end tag or the <!-- and --> script tokens, including the HTML end-tag delimiters, so any nonempty encoded substring cannot complete a delimiter supplied partly by adjacent trusted literal text. forCDATA represents every ] and > with close/reopen sequences, preserving parsed text while breaking every nonempty encoded substring of ]]>; its String facade grows with actual output instead of eagerly reserving the 13× maximum. forXmlComment replaces every hyphen with ~. These are substantial compatibility-visible output changes; see the migration record.
  • fix: EncodedWriter now enforces Writer lifecycle semantics: write, append and flush operations fail after close; repeated close is harmless; the first close finalizes pending input and still attempts the delegate close, preserving simultaneous failures with suppressed exceptions. Array-slice writes now use overflow-safe bounds validation, including Integer.MAX_VALUE-shaped ranges.
  • build: compare all three 1.5.0 artifacts against the immutable 1.4.1 public-API baseline, and verify that every publishable effective POM inherits repository-root SCM connection, developer connection and URL values without module-name suffixes.
  • feat: add Encode.forJson String/Writer methods, the json encoder context, and forJson tags and EL functions in both JSP and Jakarta tag libraries #145. The caller supplies double quotes. Output uses RFC 8259 string escapes and also escapes HTML script delimiters. Java null becomes the text null (the JSON string "null" when quoted); unpaired surrogates use Unicode escapes and may not interoperate with every JSON consumer. Prefer a serializer for complete JSON documents.
  • feat: add forXml11, forXml11Content and forXml11Attribute tags and EL functions to the advanced JSP and Jakarta taglibs, and forXml11 to the basic taglibs #131.
  • deprecation: Encoders.URI and both ForUriTag classes are now deprecated like Encode.forUri, whose Javadoc now says what to use instead; the forUri TLD descriptions warn about double encoding, the adapter builds show deprecation call sites, and the README has a forUri migration section #130.
  • fix: the JSP and Jakarta bundles now declare the core version they need ([1.5,2), because the tags call Encode.forJson) and the JSP API ranges they support, instead of unversioned imports that could wire to an older core and fail when a tag ran. Bundle symbolic names are now declared explicitly and unchanged #137.
  • fix: forHtmlUnquotedAttribute now replaces U+0085 (NEL) with a hyphen like the other C1 control characters, instead of emitting &[#133](https://github.com/OWASP/owasp-java-encoder/issues/133);, which HTML5 parsers decode as U+2026 #136.
  • fix: the XML 1.1 encoders (forXml11, forXml11Content, forXml11Attribute) now encode U+0085 (NEL) as &#x85; and U+2028 (line separator) as &#x2028;, so they are not normalized to a line feed #136.
  • maintenance: clarify output-context contracts and expand XML 1.1 tests, fix clean reactor compilation, and remove the obsolete benchmark profile.

Build, compatibility and maintenance

  • Preserve original-JAR consumers on Java 8/11/17/21/25, explicit/automatic JPMS and Felix R6/R8; add final TLD-surface/Writer contract checks (#162, #167).
  • Test packaged javax/Jakarta TLDs through isolated Tomcat/Jasper engines; retain required real-browser and executable-WAR checks with the modernized optional Boot 4.1.1 fixture (#179, #180).
  • Pin and guard Actions, add CodeQL/dependency submissions/Dependabot, isolate Maven caches, and preserve required CI/security gates (#173, #177).
  • Include Java 9 descriptors in source attachments; normalize source metadata and retain attribution (#184).
  • Retire the dormant Maven Site/OSS parent, adopt verified Maven 3.9.16 wrapper and JDK 17 build policy, Checkstyle and measured unit coverage floors; isolate signing/publishing tools, verify local bundles and measure reproducibility (#185, #187). This does not change the Java 8 library runtime baseline.
  • Add release verification, historical key evidence, and maintainer custody guidance (#164, #171, #185). Historical signing-key authorization records (#110) now distinguish retrospective maintainer authentication from historical GitHub/project records; see the key verification record. Central publication and the reported completion of maintainer access/custody work (#111) are recorded in the publication follow-up.

... (truncated)

Commits
  • 3fbc5da Prepare OWASP Java Encoder 1.5.0 release
  • df219a5 Suppress rejected Dependabot baseline updates (#228)
  • a006309 Consolidate Dependabot API updates (#217)
  • f25c771 Harden 1.5.0 context boundaries and release checks (#210)
  • 07d8e58 Complete historical key archive and maintenance closeout (#209)
  • 1111f79 Record 1.4.1 Central publication and maintainer readiness (#208)
  • 18582d3 Update bundle plugin and isolate compatibility-sensitive dependency proposals...
  • 011734a Update artifact actions with verified pins and strict digest checks (#175)
  • 21705bd Record compatibility commitments and base64url scope decision (#190)
  • 8c32b2c Consolidate consumer docs, release history and community metadata (#189)
  • Additional commits viewable in compare view

Updates org.owasp.encoder:encoder-jsp from 1.4.1 to 1.5.0

Release notes

Sourced from org.owasp.encoder:encoder-jsp's releases.

OWASP Java Encoder 1.5.0

Version 1.5.0 is available from Maven Central. All nine binary/source/Javadoc JARs, four POMs, and their thirteen signatures were downloaded from Central and verified against the retained signed release files. There is no encoder-esapi:1.5.0 release.

Security and correctness

  • Fixes encoded fragments completing outer HTML or XML parser delimiters across trusted-text boundaries in JavaScript HTML/block, CDATA, and XML-comment contexts. Versions through 1.4.1 are affected. See GHSA-g8p6-7r8f-qrpv.
  • Fixes EncodedWriter close/finalization behavior, exception handling, and overflow-safe array-slice validation.
  • Adds JSON encoding APIs and matching JSP/Jakarta tags and EL functions, plus XML 1.1 bindings.

Compatibility and migration

Public Java APIs remain binary and source compatible with 1.4.1 for the three supported libraries. Java 8 remains the minimum runtime; packaged consumers passed on Java 8, 11, 17, 21, and 25.

The security fixes deliberately change some encoded output:

  • JavaScript HTML/block modes emit additional hexadecimal escapes while preserving the string value. Review byte snapshots, cache keys, signatures, and output-size budgets.
  • CDATA preserves parsed text but can expand to 13 output characters per input character and can change parser event boundaries.
  • XML-comment hyphens become ~ under the documented lossy policy.

The optional ESAPI adapter is retired. Version 1.4.1 is its final published release and is unsupported; migrate to direct Java Encoder APIs. Mixing the 1.4.1 adapter with the 1.5 core is not a supported migration.

See the migration notes, ESAPI retirement guide, and changelog.

Maven artifacts

Use group org.owasp.encoder and version 1.5.0:

The optional test WAR and retired ESAPI adapter are not published.

Verification

Exact release source: 3fbc5da5bcdc49a6e2b4f39d3df7410b7c13d07d. The signed v1.5.0 tag identifies this tested commit. PR #229's squash commit 030c137fc14f277afc5fbe303d2ca8a149f8068b has the identical file tree.

Release artifacts were built with Eclipse Temurin 17.0.20.1+1 and the committed Maven 3.9.16 wrapper. All 2,287 local reactor tests passed with zero failures, errors, or skips. All thirteen unsigned payload files matched two fresh source-export builds. Post-merge Java CI, packaged consumers, and CodeQL passed, including the browser and Java 8 gates.

Project signing fingerprint: 1C5F632B86809F2F5DB25092BEA0075F94074A9B.

The assets contain the public KEYS, detached signatures, and signed SHA-256/SHA-512 manifests. Follow the verification instructions, using this full expected fingerprint and the 1.5.0 filenames. Authenticate each checksum manifest's signature before checking its entries.

Central bundle SHA-256: 107b0e4e1f459087d6bbd1e37222c05c7c4630fa55d52bc1e7c99c0077897590.

The source-tag documentation preserves the pre-publication notices from the immutable release commit. This release record confirms the subsequently verified Central publication; publication follow-up documentation belongs in a later commit, not a rebuilt release.

Changelog

Sourced from org.owasp.encoder:encoder-jsp's changelog.

1.5.0 — 2026-09-28 UTC

This is a security release for GHSA-g8p6-7r8f-qrpv. Signed artifact availability and independent verification are tracked in the 1.5.0 release record.

  • build: stop Dependabot from recreating already-reviewed incompatible API, servlet-engine and build-tool version proposals. The ignores are limited to routine version updates in the rejected SemVer classes; security updates remain eligible. Mixed historical/current coordinates require manual version review because Dependabot classifies them from their lowest occurrence.
  • removed: retire the optional encoder-esapi adapter. Version 1.4.1 is its final published release and is no longer supported; no encoder-esapi:1.5.0 artifact will be published. Consumers must remove the adapter and migrate Java Encoder-backed calls to the direct context APIs. Historical Maven artifacts remain immutable.
  • build: remove advisory-affected dependencies from active Maven plugin realms, including the separately invoked compatibility-fixture downloader; invoke the same japicmp engine without its obsolete reporting wrapper; and submit only actually invoked build plugins to GitHub's dependency graph. Shared inherited tooling is recorded once, and no Dependabot alert is dismissed or suppressed.
  • build/compatibility: update the published JSP provided API to 2.3.3 and the Jakarta test classpath to Servlet 6.1.0 and EL 6.0.1, while retaining independent JSP 2.2.1 and Java 8-compatible Jakarta minimum-consumer fixtures. Japicmp now resolves distinct old/new support classpaths so the 1.4.1 comparison remains complete. Dependabot scans the root Maven reactor once, rather than opening duplicate module proposals, and continues to scan the standalone compatibility-fixture project separately.
  • feat: all four forJavaScript* methods encode dollar sign ($) as \x24, backtick as \x60, and opening brace ({) as \x7b #129. Escaping { prevents input after a trusted $ from completing ${...}. Encoded output now supports literal text in ordinary (untagged) template literals as well as single- and double-quoted strings. This changes the encoded output while preserving its decoded JavaScript string value. Tagged templates (including String.raw), ${...} expression bodies, JSON, and script URLs are unsupported; each method's HTML context restrictions still apply.
  • fix: all four forJavaScript* methods escape unpaired UTF-16 surrogates as \uXXXX, preserving their JavaScript string values through UTF-8 serialization #135, and escape DEL/C1 controls (U+007F to U+009F) as \xNN #163. Valid surrogate pairs and other non-ASCII text remain unescaped except U+2028/U+2029. These are output-fidelity changes; NEL was already ordinary JavaScript string data.
  • fix: the HTML/block JavaScript encoders escape every ASCII character that can contribute to a case-insensitive </script end tag or the <!-- and --> script tokens, including the HTML end-tag delimiters, so any nonempty encoded substring cannot complete a delimiter supplied partly by adjacent trusted literal text. forCDATA represents every ] and > with close/reopen sequences, preserving parsed text while breaking every nonempty encoded substring of ]]>; its String facade grows with actual output instead of eagerly reserving the 13× maximum. forXmlComment replaces every hyphen with ~. These are substantial compatibility-visible output changes; see the migration record.
  • fix: EncodedWriter now enforces Writer lifecycle semantics: write, append and flush operations fail after close; repeated close is harmless; the first close finalizes pending input and still attempts the delegate close, preserving simultaneous failures with suppressed exceptions. Array-slice writes now use overflow-safe bounds validation, including Integer.MAX_VALUE-shaped ranges.
  • build: compare all three 1.5.0 artifacts against the immutable 1.4.1 public-API baseline, and verify that every publishable effective POM inherits repository-root SCM connection, developer connection and URL values without module-name suffixes.
  • feat: add Encode.forJson String/Writer methods, the json encoder context, and forJson tags and EL functions in both JSP and Jakarta tag libraries #145. The caller supplies double quotes. Output uses RFC 8259 string escapes and also escapes HTML script delimiters. Java null becomes the text null (the JSON string "null" when quoted); unpaired surrogates use Unicode escapes and may not interoperate with every JSON consumer. Prefer a serializer for complete JSON documents.
  • feat: add forXml11, forXml11Content and forXml11Attribute tags and EL functions to the advanced JSP and Jakarta taglibs, and forXml11 to the basic taglibs #131.
  • deprecation: Encoders.URI and both ForUriTag classes are now deprecated like Encode.forUri, whose Javadoc now says what to use instead; the forUri TLD descriptions warn about double encoding, the adapter builds show deprecation call sites, and the README has a forUri migration section #130.
  • fix: the JSP and Jakarta bundles now declare the core version they need ([1.5,2), because the tags call Encode.forJson) and the JSP API ranges they support, instead of unversioned imports that could wire to an older core and fail when a tag ran. Bundle symbolic names are now declared explicitly and unchanged #137.
  • fix: forHtmlUnquotedAttribute now replaces U+0085 (NEL) with a hyphen like the other C1 control characters, instead of emitting &[#133](https://github.com/OWASP/owasp-java-encoder/issues/133);, which HTML5 parsers decode as U+2026 #136.
  • fix: the XML 1.1 encoders (forXml11, forXml11Content, forXml11Attribute) now encode U+0085 (NEL) as &#x85; and U+2028 (line separator) as &#x2028;, so they are not normalized to a line feed #136.
  • maintenance: clarify output-context contracts and expand XML 1.1 tests, fix clean reactor compilation, and remove the obsolete benchmark profile.

Build, compatibility and maintenance

  • Preserve original-JAR consumers on Java 8/11/17/21/25, explicit/automatic JPMS and Felix R6/R8; add final TLD-surface/Writer contract checks (#162, #167).
  • Test packaged javax/Jakarta TLDs through isolated Tomcat/Jasper engines; retain required real-browser and executable-WAR checks with the modernized optional Boot 4.1.1 fixture (#179, #180).
  • Pin and guard Actions, add CodeQL/dependency submissions/Dependabot, isolate Maven caches, and preserve required CI/security gates (#173, #177).
  • Include Java 9 descriptors in source attachments; normalize source metadata and retain attribution (#184).
  • Retire the dormant Maven Site/OSS parent, adopt verified Maven 3.9.16 wrapper and JDK 17 build policy, Checkstyle and measured unit coverage floors; isolate signing/publishing tools, verify local bundles and measure reproducibility (#185, #187). This does not change the Java 8 library runtime baseline.
  • Add release verification, historical key evidence, and maintainer custody guidance (#164, #171, #185). Historical signing-key authorization records (#110) now distinguish retrospective maintainer authentication from historical GitHub/project records; see the key verification record. Central publication and the reported completion of maintainer access/custody work (#111) are recorded in the publication follow-up.

... (truncated)

Commits
  • 3fbc5da Prepare OWASP Java Encoder 1.5.0 release
  • df219a5 Suppress rejected Dependabot baseline updates (#228)
  • a006309 Consolidate Dependabot API updates (#217)
  • f25c771 Harden 1.5.0 context boundaries and release checks (#210)
  • 07d8e58 Complete historical key archive and maintenance closeout (#209)
  • 1111f79 Record 1.4.1 Central publication and maintainer readiness (#208)
  • 18582d3 Update bundle plugin and isolate compatibility-sensitive dependency proposals...
  • 011734a Update artifact actions with verified pins and strict digest checks (#175)
  • 21705bd Record compatibility commitments and base64url scope decision (#190)
  • 8c32b2c Consolidate consumer docs, release history and community metadata (#189)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `owasp.encoder.version` from 1.4.1 to 1.5.0.

Updates `org.owasp.encoder:encoder` from 1.4.1 to 1.5.0
- [Release notes](https://github.com/OWASP/owasp-java-encoder/releases)
- [Changelog](https://github.com/OWASP/owasp-java-encoder/blob/main/CHANGELOG.md)
- [Commits](OWASP/owasp-java-encoder@v1.4.1...v1.5.0)

Updates `org.owasp.encoder:encoder-jsp` from 1.4.1 to 1.5.0
- [Release notes](https://github.com/OWASP/owasp-java-encoder/releases)
- [Changelog](https://github.com/OWASP/owasp-java-encoder/blob/main/CHANGELOG.md)
- [Commits](OWASP/owasp-java-encoder@v1.4.1...v1.5.0)

---
updated-dependencies:
- dependency-name: org.owasp.encoder:encoder
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: org.owasp.encoder:encoder-jsp
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 2, 2026
@dschadow
dschadow merged commit bf77c7f into main Oct 2, 2026
3 checks passed
@dschadow
dschadow deleted the dependabot/maven/owasp.encoder.version-1.5.0 branch October 2, 2026 05:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant