-
-
Notifications
You must be signed in to change notification settings - Fork 128
Clarify ESAPI dependency policy by release and preserve the 1.4.1 upgrade warning #112
Copy link
Copy link
Closed
Labels
area: docsConsumer/contributor documentation and project metadata.Consumer/contributor documentation and project metadata.documentationpriority: P1High priority: security contracts, CI protection or consumer compatibility.High priority: security contracts, CI protection or consumer compatibility.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.Security-sensitive scope or acceptance criteria; not a vulnerability classification.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.Scope reviewed; actionable within its batch, subject to the normal PR process.
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
area: docsConsumer/contributor documentation and project metadata.Consumer/contributor documentation and project metadata.documentationpriority: P1High priority: security contracts, CI protection or consumer compatibility.High priority: security contracts, CI protection or consumer compatibility.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.Security-sensitive scope or acceptance criteria; not a vulnerability classification.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.Scope reviewed; actionable within its batch, subject to the normal PR process.
Reviewed 2026-09-25 (America/Los_Angeles) against
mainatbd249f5. Execution order and cross-issue ownership: #169. Batch 00.This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.
Current state
esapi/README.mdstill says the published POM defaults to ESAPI 2.7.0.0 without naming the adapter version. The 1.4.0 POM uses[2.5.1.0,3); #99 fixed the dependency and the signed GitHub 1.4.1 release includes it. Central publication is still pending (#111). The old statement that no tag contains the fix is obsolete.Acceptance criteria
dependencyManagementpin for consumers temporarily remaining on 1.4.0, while clearly stating that pinning ESAPI does not fix Java Encoder's published 1.4.1 security advisories; upgrade the encoder as well.The broader README rewrite is #128 and need not delay this consumer-facing correction.
Batch 00 implementation — 2026-09-25 (America/Los_Angeles)
#171 merged the documentation and installation guidance as
6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6fat 2026-09-26 05:00:48 UTC. All 20 GitHub checks passed on the PR head. Jim explicitly directed the merge after the normal approving-review gate blocked it; the administrator override was used. Maven 3.9.12 / OpenJDK 17.0.20.1 validated both README XML examples in separate fresh repositories with empty user/global settings: 1.4.0 plus the management pin resolves ESAPI 2.7.0.0 but retains core 1.4.0; verified signed 1.4.1 resolves core/adapter 1.4.1 and ESAPI 2.7.0.0. All five documented artifact installations passed without rebuilding.The 1.4.0 GitHub release notes now carry the narrowly scoped dated pin/upgrade supplement. Original release text and asset metadata were verified unchanged apart from that supplement. Upstream's latest release and security policy were rechecked and identify ESAPI 2.7.0.0 as current and supported. Central 1.4.1 publication remains pending under #111.
Validation evidence. Closed by the merge of #171. Central publication and the remaining operational checks stay open under #111.