You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Repository settings checked on 2026-09-23 show no way to scope or prioritize open work. The repository has zero milestones, the only labels are the nine stock ones (bug, dependencies, documentation, duplicate, enhancement, help wanted, invalid, question, wontfix), and none of the twelve open issues (#91-#105) or the two open PRs (#98, #106) is assigned to a release. Open issues carry only a type label (bug, enhancement, documentation); there are no area or priority labels. Two of the open items change adapter behavior (#100, the ESAPI adapter strictness change, and #92/#98, requires transitive in the adapter module descriptors), so without release scoping the next patch release risks carrying behavior changes alongside fixes, and the 2.0 decisions keep being deferred.
Evidence
gh api repos/OWASP/owasp-java-encoder/milestones?state=all
[]
Every open issue and PR prints no milestone. .github/ contains only workflows/; there is no ISSUE_TEMPLATE/ and no CONTRIBUTING.md.
Historical triage data from gh api repos/OWASP/owasp-java-encoder/issues?state=all (68 issues, 36 PRs): 56 closed issues with a median time to close of 72.0 days, 90th percentile about 525 days, maximum 1,934 days (#36, 2020-07-28 to 2025-11-13). Five externally opened issues (#3, #21, #26, #50, #81) never received a maintainer comment. The last externally opened issue is #81 (2024-08-18); all 13 issues since are maintainer-filed. PRs from the last two years close in a median of 0.2 days, so review capacity is not the bottleneck; scoping and visibility are.
PR #98 (fix for #92) is approved but is now mergeable=false, mergeable_state=dirty against main after #99 merged, and is drifting.
Acceptance criteria
Milestones 1.4.1, 1.5.0 and 2.0.0 exist:
gh api -X POST repos/OWASP/owasp-java-encoder/milestones -f title=1.4.1
gh api -X POST repos/OWASP/owasp-java-encoder/milestones -f title=1.5.0
gh api -X POST repos/OWASP/owasp-java-encoder/milestones -f title=2.0.0
Labels area/core, area/jsp, area/jakarta, area/esapi, area/build-ci, area/docs, priority/high, priority/normal, status/needs-info and good first issue exist alongside the existing type labels:
The triage targets (first maintainer response within 7 days, label and milestone within 14 days) are adopted and applied to the items above; publishing them in CONTRIBUTING.md is tracked separately with the other community files.
Problem
Repository settings checked on 2026-09-23 show no way to scope or prioritize open work. The repository has zero milestones, the only labels are the nine stock ones (
bug,dependencies,documentation,duplicate,enhancement,help wanted,invalid,question,wontfix), and none of the twelve open issues (#91-#105) or the two open PRs (#98, #106) is assigned to a release. Open issues carry only a type label (bug,enhancement,documentation); there are no area or priority labels. Two of the open items change adapter behavior (#100, the ESAPI adapter strictness change, and #92/#98,requires transitivein the adapter module descriptors), so without release scoping the next patch release risks carrying behavior changes alongside fixes, and the 2.0 decisions keep being deferred.Evidence
Every open issue and PR prints no milestone.
.github/contains onlyworkflows/; there is noISSUE_TEMPLATE/and noCONTRIBUTING.md.Historical triage data from
gh api repos/OWASP/owasp-java-encoder/issues?state=all(68 issues, 36 PRs): 56 closed issues with a median time to close of 72.0 days, 90th percentile about 525 days, maximum 1,934 days (#36, 2020-07-28 to 2025-11-13). Five externally opened issues (#3, #21, #26, #50, #81) never received a maintainer comment. The last externally opened issue is #81 (2024-08-18); all 13 issues since are maintainer-filed. PRs from the last two years close in a median of 0.2 days, so review capacity is not the bottleneck; scoping and visibility are.PR #98 (fix for #92) is approved but is now
mergeable=false,mergeable_state=dirtyagainstmainafter #99 merged, and is drifting.Acceptance criteria
1.4.1,1.5.0and2.0.0exist:area/core,area/jsp,area/jakarta,area/esapi,area/build-ci,area/docs,priority/high,priority/normal,status/needs-infoandgood first issueexist alongside the existing type labels:area/*andpriority/*names)area/*label.1.4.1contains no item that changes encoder or adapter output. Suggested starting split, subject to maintainer judgment:1.4.1= jakarta-test pins encoder-jakarta-jsp to 1.4.0 and will test the published jar after a version bump #101/Keep jakarta-test on the reactor's encoder-jakarta-jsp version #106, Pin every GitHub Actions workflow dependency to a verified commit SHA #102, Make release artifacts reproducible with a recorded reference toolchain #103, Fix Javadoc and TLD descriptions that disagree with encoder behavior #105;1.5.0= Fix JPMS dependency reads in the JSP, Jakarta, and ESAPI adapters #92/Fix JPMS dependency reads in adapter modules #98, Align ESAPI URL-component semantics and define safe adapter context contracts #100 (with a release-notes entry for the output change), Add consumer compatibility CI across supported JDKs and all published JARs #91, Decide and modernize the optional browser integration fixture without losing coverage #93, Retire unused site tooling while preserving documentation and useful reports #96, Add code scanning, grouped dependency updates and resolved dependency visibility #97;2.0.0= breaking changes only, such as removal of the deprecatedEncode.forUristill shipped atcore/src/main/java/org/owasp/encoder/Encode.java:664; Modernize release tooling and validate future releases without replacing 1.4.1 #95 and Pin supported Maven build plugins and centralize plugin-version enforcement #104 are assigned once their remaining scope is decided.mainand merged, or retargeted to1.5.0;1.4.1is not held for it.CONTRIBUTING.mdis tracked separately with the other community files.Related: #91, #92, #93, #95, #96, #97, #98, #100, #101, #102, #103, #104, #105, #106
Suggested target: 1.4.1