Skip to content

Clarify ESAPI dependency policy by release and preserve the 1.4.1 upgrade warning #112

Description

@jmanico

Reviewed 2026-09-25 (America/Los_Angeles) against main at bd249f5. Execution order and cross-issue ownership: #169. Batch 00.

This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.

Current state

esapi/README.md still says the published POM defaults to ESAPI 2.7.0.0 without naming the adapter version. The 1.4.0 POM uses [2.5.1.0,3); #99 fixed the dependency and the signed GitHub 1.4.1 release includes it. Central publication is still pending (#111). The old statement that no tag contains the fix is obsolete.

Acceptance criteria

  • Distinguish 1.4.0's version range, the fixed 2.7.0.0 default in the signed 1.4.1 artifacts, and unreleased 1.5 development. Check current upstream stable/support information before calling a dependency "latest".
  • Add the dependencyManagement pin for consumers temporarily remaining on 1.4.0, while clearly stating that pinning ESAPI does not fix Java Encoder's published 1.4.1 security advisories; upgrade the encoder as well.
  • Link the signed 1.4.1 artifacts and verification instructions while Central is pending. Coordinate wording with Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 and remove pending wording only after Central verification.
  • Add the narrowly scoped pin/upgrade advice to the 1.4.0 release notes without rewriting historical artifacts or signatures.
  • Verify example dependency resolution in an isolated Maven repository and retain the distinction between adapter compatibility and upstream security support.

The broader README rewrite is #128 and need not delay this consumer-facing correction.

Batch 00 implementation — 2026-09-25 (America/Los_Angeles)

#171 merged the documentation and installation guidance as 6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6f at 2026-09-26 05:00:48 UTC. All 20 GitHub checks passed on the PR head. Jim explicitly directed the merge after the normal approving-review gate blocked it; the administrator override was used. Maven 3.9.12 / OpenJDK 17.0.20.1 validated both README XML examples in separate fresh repositories with empty user/global settings: 1.4.0 plus the management pin resolves ESAPI 2.7.0.0 but retains core 1.4.0; verified signed 1.4.1 resolves core/adapter 1.4.1 and ESAPI 2.7.0.0. All five documented artifact installations passed without rebuilding.

The 1.4.0 GitHub release notes now carry the narrowly scoped dated pin/upgrade supplement. Original release text and asset metadata were verified unchanged apart from that supplement. Upstream's latest release and security policy were rechecked and identify ESAPI 2.7.0.0 as current and supported. Central 1.4.1 publication remains pending under #111.

Validation evidence. Closed by the merge of #171. Central publication and the remaining operational checks stay open under #111.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: docsConsumer/contributor documentation and project metadata.documentationpriority: P1High priority: security contracts, CI protection or consumer compatibility.security-reviewSecurity-sensitive scope or acceptance criteria; not a vulnerability classification.triage: readyScope reviewed; actionable within its batch, subject to the normal PR process.

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions