You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reviewed the complete open inventory on 2026-09-25 (America/Los_Angeles): 30 issues and 1 PR, against main at bd249f5. Read all issue bodies and discussion comments, reviewed the open PR diff/checks, compared recent merged/closed work, and rechecked relevant repository settings and Central availability. This tracker records the execution order; it does not implement or release the batches.
How to work this queue
Use the numbered milestones in order, with the dependencies below controlling merge order. Work that is independent and ready may proceed while external access or a preceding decision is blocked. priority: P0/P1/P2/P3 indicates urgency, area:* ownership, and triage:* disposition. security-review marks sensitive acceptance criteria, not a vulnerability classification. Keep batches reviewable; a batch need not be one giant PR.
Correct consumer guidance now; finish exact signed 1.4.1 Central delivery when namespace access permits. Independent vault/access checks need actual evidence.
Pin/guard first, add scanning and updates, preserve complete CI gates, then enforce settings that depend on them. Independent settings hardening can start now.
Normalize and decide site scope; coordinate toolchain/release changes; measure reproducibility and quality. Re-run final byte comparison after byte-affecting changes. Historical key records can proceed independently.
PR #168 at 7bfa00f3242c8918b7d201c8e55bbd7b1b31e00e contains delegating tag/TLD/test/doc changes with no core algorithm or dependency change. No new security regression identified in its diff. All 20 GitHub checks passed at review time, and independent local parity validation passed across 33 source files. A full local Maven rerun was not performed because Maven was unavailable in this session's PATH. Independent maintainer review remains required; triage did not approve or merge it. Its delivery batch includes the existing OSGi minimum-core problem.
Completion evidence and release gate
All initially open issues/PRs reviewed and assigned priority, area, disposition and numbered milestone.
Duplicated responsibilities consolidated; obsolete version assumptions and dangerous acceptance criteria corrected.
PR diff/checks reviewed and limits of local verification recorded.
For each batch, record merged PRs, validation and remaining blockers/explicit dispositions here as work completes.
Before any 1.5 release, re-inventory all then-open issues and PRs and satisfy the full backlog gate in RELEASING.md. Labeling, deferring, moving milestones or completing one batch is not release approval.
This tracker is the cross-batch index and intentionally has no single batch milestone. No source code, repository security setting, release asset, tag or PR merge is changed by this organization pass.
Implementation: #171 merged at 2026-09-26 05:00:48 UTC as 6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6f. All 20 GitHub checks passed on the PR head. After the normal merge was blocked by the approving-review requirement, Jim explicitly directed the merge and the administrator override was used. #112 is closed; batch 00 remains operationally incomplete under #111.
Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111: verified all 19 signatures and signed manifests, plus every artifact, signature, and checksum in the retained Central bundle. Bundle SHA-256: c70234d2290fff0011d484219b7bc8fae2581cf24b24b03abf5eab4413b6d4c3. All five exact Central 1.4.1 POMs still return 404. Jim's signed-in Portal shows no namespaces and disabled publishing. Initial key setup was confirmed by Jim; neither an independent vault drill nor a staging rehearsal was confirmed. Jeremy's checks remain unconfirmed. No bundle was rebuilt, re-signed, uploaded, or republished; continue the existing Support request.
Remaining: publisher namespace access; exact 1.4.1 publication and comparison; each custodian's independent vault drill and each publisher's distinct validated-then-dropped rehearsal; post-publication notices and destinations. The OWASP project page still refers to 1.3.0 and javadoc.io to 1.4.0. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 stays open, and the full 1.5 release gate remains unchanged.
Validation: local clean verify passed 2,126 tests plus API and Java 8 signature checks; all 16 focused adapter tests passed on each of ten stable ESAPI versions. Independent URL/HTML parsing covers delimiter and markup boundaries. Packaged consumers passed locally on Java 17 and in CI on Java 8/11/17/21/25, including URL/null checks on classpath, module path, and OSGi. Browser checks, Java 8 unit tests, all matrix checks, final Javadocs, all eight legacy TLD descriptions, and 31-file JSP/Jakarta parity passed.
Delivery:ci: complete batch 02 security and compatibility controls #173 merged as f8586a6bfe5b326e5f860ae55cbb4b74a8e0e1a2 at 2026-09-26 05:52:52 UTC after all 26 GitHub checks passed on 659e6e2f1a73df4b35f7315803b1db53fac1150a. The live graph check exposed GitHub detector precedence masking runtime edges, so ci: preserve runtime and build dependencies in GitHub graphs #177 aligned the detector identities; it merged as d4562ec5bbe833a436ef7459b1d2d42ca926b2bf at 06:03:00 UTC after all 26 checks passed on 166ed8c5e820ea13b8c67e9025fc98a0362486ec. Jim instructed completion and merge. The normal independent-review gate remained active; the explicitly configured, audit-visible PR-only maintainer review bypass was used for these merges. Required CI/security checks have no bypass and all passed. This is not recorded as independent approval.
Harden repository settings in stages after verifying CI and release-tag protections #108: enabled secret scanning/push protection, read-only default tokens, no Actions PR approvals, approval for all external fork runs, Pages HTTPS, the exact action allowlist/full-SHA policy, and all-tag update/deletion protection. Disabled both failing legacy webhooks while retaining their configuration. Main requires both compatibility gates and all three CodeQL jobs, bound to GitHub Actions, with strict current-base checks. Review rules retain one approval/stale dismissal and add latest-push approval/resolved threads. The old all-admin always-bypass is removed; only Jim and Jeremy can use a PR-only review bypass. GitHub rejected the verified team actor, so supported individual user actors are configured. CODEOWNERS validation stays with Add accurate contributor guidance and validated community/review metadata #127; signed-tag verification is separate from commit-signature rules.
Validation and negative cases: local fresh-repository JDK 17 clean verify passed 2,126 tests, API/signature checks, Java 17 packaged consumers and 11 package guard tests. Actionlint and 10 policy/parser tests pass. Live probes rejected mutable action tags, unlisted pinned GitHub-owned actions, tag update/deletion, and direct branch updates missing a PR/five checks. The allowlist probe caught and corrected an API reset of the blanket GitHub-owned allowance. Every original tag is unchanged. The actual external fork PR Add XML 1.1 tags and EL functions to both taglibs #168's read-only/no-secrets run and the new workflow boundaries were inspected; the evidence documents the limit that a new external-fork CodeQL run was not manufactured. All final-main workflows passed: Java CI, packaged consumers, CodeQL, and dependency submission above. One PR ESAPI runner failed before tests with a Maven Central HTTP 403; its failed-job rerun passed.
Constrain OSGi imports to actual adapter API requirements and freeze bundle identities #137 / Declare OSGi import ranges from actual API use and freeze bundle names #174: reviewed and approved the contributor's OSGi change at 28b57eb7d6cfb7b01dcbf7484da9d471e3ed1d3c, then merged normally as 159041aa5a668483d456d3c9e8e4a673b697e6cb after all 26 checks passed. Symbolic names are explicit and preserved, JSP/Jakarta core imports require [1.5,2) for JSON linkage, ESAPI uses the supported 1.4.1 security floor, and API ranges remain conservative. Real Felix R6/R8 consumers accept supported wiring and reject core 1.4.0; classpath/JPMS JSON linkage and 15 package guards pass. No embedded dependencies or new library/API baseline.
Add XML 1.1 tags and EL functions to both taglibs #131 / Add XML 1.1 tags and EL functions to both taglibs #168: reviewed and approved at ece754c3a094f591dc23213f317735f1b237b706, then merged normally as 2b8e7b3a90895fbcacb89c3b2894c461dc71843d after all 26 checks passed. Both adapters expose the three XML 1.1 contexts in advanced descriptors and forXml11 in basic descriptors, with direct Writer delegation and context restrictions. The intended forJava omission remains explicit. Existing contract tests expand automatically; 34-file JSP/Jakarta parity passes.
Render every current JSP and Jakarta tag/EL binding through isolated JSP engines #120 / Test every packaged taglib binding through real JSP engines #179: merged as e6bbebe8e8ee9043e9cd1328fdda18b3e55816b2 after all 26 checks passed on 96a1c64d0878fedf6919d6cadb65e542a974986f. Normal Docker-free verify now forks isolated maintained Tomcat/Jasper 9.0.122 and 10.1.60 engines. The actual packaged TLDs generate 144 bindings across both adapters, 1,152 complete response-byte assertions, and 144 JSP translation rejections for bodies/missing attributes. Coverage includes JSON/XML 1.1, hostile markup/Unicode/controls, buffer boundaries, null/missing values and EL coercion. Engine dependencies stay outside library test/runtime classpaths. Local clean verify passed 2,178 unit plus eight existing integration tests, API/signatures and the new engines; CI retains the Java 8/11/17/21/25 matrix and browser checks.
Decide and modernize the optional browser integration fixture without losing coverage #93 / Retain and modernize required browser and packaged WAR coverage #180: merged as 111d03390b96bba9fce33474cef413f8b07b6288 after all 26 checks passed on d215dc02f275d8cd9914fbaf6dd50cb8197e9446. Explicit decision: retain the required actual-browser suite because facade byte comparisons cannot replace its DOM, HTML parser and JavaScript grammar assertions. The optional fixture now uses supported Boot 4.1.1, coherent Tomcat 11.0.26 APIs, Testcontainers 2.0.5 and aligned Selenium 4.49.0; library support baselines remain unchanged. Browser/helper images are pinned by verified registry index digest, discarded recording is disabled, and browser/container/server cleanup is explicit. The executable WAR itself is launched and its packaged JSP/JSTL views and exact encoded cells are verified. Removed unused JSON/service/test scaffolding and duplicate API JARs while retaining required JSTL. The 34 packaged third-party coordinates returned no OSV advisories at review time; this does not cover OS images, build plugins or test-only dependencies.
Requested reviews: Sol reviewed all batch 02/03 changes in three scopes and independently read back the live repository controls. Its browser review identified unused JSP sessions rewriting a test URL; setting session=false fixed the startup assertion and the packaged test passed. Sol found no remaining actionable issues. Astra's final complete-diff review at 413177ce found no actionable correctness/security findings and independently passed 10 policy/parser tests, 15 artifact guards, parity, and exact WAR/JAR comparison. CI then exposed Testcontainers image-name compatibility handling; an explicit declaration retained the exact digest, and Astra reviewed the correction through d215dc02 with no findings. AI review is not recorded as independent maintainer approval. Jim explicitly directed review and merge; Test every packaged taglib binding through real JSP engines #179 and Retain and modernize required browser and packaged WAR coverage #180 used the documented PR-only review bypass, while required CI/security checks have no bypass and passed.
Final verification and cleanup: All 26 final PR checks passed, including five JavaScript browser tests, the server-rendered DOM test, executable-WAR test, exact reactor JAR inclusion, all required compatibility legs and CodeQL. All final-main workflows also passed: Java CI, packaged consumers, CodeQL, and dependency submission. All four batch issues are closed. Returned to clean synchronized main; removed the merged task/review branches and retained contributor fork branches, active Pages and unrelated work. The open automated dependency PRs remain for deliberate review in their owning batches. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 and the full 1.5 release gate remain unchanged. Continue with batch 04 as directed.
Batch 04 — implementation merged; historical-key evidence gap remains
All 28 checks passed on PR Modernize build policy and verify release artifacts #185 head 8d761d5c886455830dde0fc4600fc3747ddd5350: Docker/browser/WAR, ten ESAPI versions, Windows/Unix bootstrap with bad-hash rejection, Java 8 unit JVM, original-JAR consumers on 8/11/17/21/25, and CodeQL. Full local verify, 17 artifact guards, parity, coverage regression/skip probes and Java 17 packaged consumers also passed.
Two separate clean exports of the same source commit, with fresh repositories and the reference Temurin 17.0.20.1+1/Maven 3.9.16, produced 12 byte-identical JARs and five identical POMs. A disposable local-only test key validated all 17 signatures, 68 checksums and a 102-entry bundle. Wrong-key, stale-POM, tamper, missing-key and SNAPSHOT-release failures were verified. No production key/token, Portal upload or release tag was used. Disposable signing private material was removed.
Sol's review found an inaccurate migrated Central example and optimization-sensitive Python assertions. Both were fixed; 14 policy/verification tests now include optimized-mode regression probes. Sol re-review and final Astra review found no remaining actionable findings. Astra independently checked the tests, retained comparison payloads and wrapper provenance. Model review is not independent maintainer approval.
Reference toolchain, Checkstyle Java 17 compatibility exception, descriptor parser exclusion, unit-only coverage scope and publisher-plugin mitigation limits are explicit in BUILDING.md, RELEASING.md, and batch 04 validation.
The broader resolved signing/publishing dependency audit led to PR #187, merged as 3bd86250a9c9cd48577c3bf7fb9c46dbe91c1c90 at 2026-09-26 07:35:25 UTC. Bouncy Castle pg/prov/util are aligned at 1.86 and both release plugins use compatible Plexus Utils 3.6.2, confined to plugin dependencies. All 28 final-head checks passed on 0cb11a6a3bf2c842793c135df62fb9e9eaf2fd64; Sol and then Astra independently reviewed the diff and validation evidence with no actionable findings. The authorized PR-only review bypass was used; required CI/security checks have no bypass and passed. Model review is not independent maintainer approval.
Repeated the two-clean-build comparison after the POM change: all 17 payloads matched, and only the parent POM changed versus Modernize build policy and verify release artifacts #185. Both default GnuPG and optional Bouncy Castle signing passed with a new disposable local-only key; each set of 17 signatures verified and produced a 102-entry bundle. The full actual GPG/Central closure, 28 distinct coordinates including plugin roots, returned no OSV matches on 2026-09-26. The checked-in validation record contains all coordinates, payload hashes and both bundle hashes. This does not certify the entire build graph or live Central transport; other scoped dependency alerts remain visible.
All four post-merge workflows passed on final main 3bd8625: Java CI, packaged consumers, CodeQL, and dependency submission. Live SBOM readback confirms BC 1.86/Plexus 3.6.2 and Central 0.11.0 alongside runtime/test ESAPI 2.7.0.0 and Jasper 9.0.122/10.1.60/11.0.26; the release and runtime graphs coexist.
Back on clean, synchronized main; all merged task branches, generated targets/bytecode caches, isolated Maven/wrapper repositories and downloaded reference JDK were removed. Disposable signing private material was deleted, compact validation evidence retained, and unrelated branches/Pages/user Maven storage preserved. Eight batch 04 issues are closed; Complete historical release-key records and verify consumer instructions #110 remains open for its four historical authorization-record gaps. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 retains Central access, independent custody and real validated-and-dropped staging rehearsals. The 1.5 release gate remains in force; no tagging/publication was authorized by this maintenance batch.
Reviewed the complete open inventory on 2026-09-25 (America/Los_Angeles): 30 issues and 1 PR, against
mainatbd249f5. Read all issue bodies and discussion comments, reviewed the open PR diff/checks, compared recent merged/closed work, and rechecked relevant repository settings and Central availability. This tracker records the execution order; it does not implement or release the batches.How to work this queue
Use the numbered milestones in order, with the dependencies below controlling merge order. Work that is independent and ready may proceed while external access or a preceding decision is blocked.
priority: P0/P1/P2/P3indicates urgency,area:*ownership, andtriage:*disposition.security-reviewmarks sensitive acceptance criteria, not a vulnerability classification. Keep batches reviewable; a batch need not be one giant PR.Consolidation and single owners
Security and compatibility corrections made during organization
[1.4,2)is insufficient for JSP/Jakarta tags now calling the 1.5 JSON API. Derive supported ranges and exercise actual linkage.Open PR review
PR #168 at
7bfa00f3242c8918b7d201c8e55bbd7b1b31e00econtains delegating tag/TLD/test/doc changes with no core algorithm or dependency change. No new security regression identified in its diff. All 20 GitHub checks passed at review time, and independent local parity validation passed across 33 source files. A full local Maven rerun was not performed because Maven was unavailable in this session's PATH. Independent maintainer review remains required; triage did not approve or merge it. Its delivery batch includes the existing OSGi minimum-core problem.Completion evidence and release gate
RELEASING.md. Labeling, deferring, moving milestones or completing one batch is not release approval.This tracker is the cross-batch index and intentionally has no single batch milestone. No source code, repository security setting, release asset, tag or PR merge is changed by this organization pass.
Batch 00 progress — 2026-09-25 (America/Los_Angeles)
Implementation: #171 merged at 2026-09-26 05:00:48 UTC as
6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6f. All 20 GitHub checks passed on the PR head. After the normal merge was blocked by the approving-review requirement, Jim explicitly directed the merge and the administrator override was used. #112 is closed; batch 00 remains operationally incomplete under #111.c70234d2290fff0011d484219b7bc8fae2581cf24b24b03abf5eab4413b6d4c3. All five exact Central 1.4.1 POMs still return 404. Jim's signed-in Portal shows no namespaces and disabled publishing. Initial key setup was confirmed by Jim; neither an independent vault drill nor a staging rehearsal was confirmed. Jeremy's checks remain unconfirmed. No bundle was rebuilt, re-signed, uploaded, or republished; continue the existing Support request.Detailed validation evidence.
Batch 01 complete — 2026-09-25 (America/Los_Angeles)
813f01070142af7e172ce4256f9910d1e13ddf6a, approved, and merged Propagate the forUri deprecation to Encoders, tags and TLDs #170 as98608dd52c46e4f250e5eff4d3a6fda218a22dd3. All 20 PR checks passed; local integration and JSP/Jakarta parity passed. Registry/tag annotations, generated deprecation descriptions, migration guidance, and focused compiler diagnostics retain the existing 1.x APIs and behavior.fe5e0ad174481c2f23a566aa33069a0e45562785at 2026-09-26 05:20:26 UTC. All 20 PR checks passed on4a7c7466142be434513ff27abb3a830fd1d9e878. Jim directed review and merge; the administrator override was used for the approving-review requirement. The adapter now encodes one raw URL component using UTF-8 and%20spaces, preserving its null, malformed-Unicode, checked-exception, and lazy-configuration contracts. The output change is explicitly unreleased 1.5 behavior. The quoted HTML/CSS/JavaScript contracts and existing security fixes remain intact.clean verifypassed 2,126 tests plus API and Java 8 signature checks; all 16 focused adapter tests passed on each of ten stable ESAPI versions. Independent URL/HTML parsing covers delimiter and markup boundaries. Packaged consumers passed locally on Java 17 and in CI on Java 8/11/17/21/25, including URL/null checks on classpath, module path, and OSGi. Browser checks, Java 8 unit tests, all matrix checks, final Javadocs, all eight legacy TLD descriptions, and 31-file JSP/Jakarta parity passed.forUribehavior remains unchanged through 1.x; no removal decision or 1.5 release is authorized. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 remains operationally blocked as recorded above. Next implementation batch: 02.Batch 02 complete — 2026-09-25 (America/Los_Angeles)
f8586a6bfe5b326e5f860ae55cbb4b74a8e0e1a2at 2026-09-26 05:52:52 UTC after all 26 GitHub checks passed on659e6e2f1a73df4b35f7315803b1db53fac1150a. The live graph check exposed GitHub detector precedence masking runtime edges, so ci: preserve runtime and build dependencies in GitHub graphs #177 aligned the detector identities; it merged asd4562ec5bbe833a436ef7459b1d2d42ca926b2bfat 06:03:00 UTC after all 26 checks passed on166ed8c5e820ea13b8c67e9025fc98a0362486ec. Jim instructed completion and merge. The normal independent-review gate remained active; the explicitly configured, audit-visible PR-only maintainer review bypass was used for these merges. Required CI/security checks have no bypass and all passed. This is not recorded as independent approval.verify; all Maven storage is isolated and uncached, including the necessary Java 8install. Two required fail-closed gates retain clean reactor/API/Java 8 signatures, all ten ESAPI versions, JSP/Jakarta parity, Docker/browser coverage, Java 8 unit tests, and original packaged consumers on Java 8/11/17/21/25. The optional Jakarta WAR contains the byte-identical reactor JAR without an install. Timeouts, cancellation, schedules, manual dispatch and diagnostic retention are present; newer-JDK build probes remain advisory.clean verifypassed 2,126 tests, API/signature checks, Java 17 packaged consumers and 11 package guard tests. Actionlint and 10 policy/parser tests pass. Live probes rejected mutable action tags, unlisted pinned GitHub-owned actions, tag update/deletion, and direct branch updates missing a PR/five checks. The allowlist probe caught and corrected an API reset of the blanket GitHub-owned allowance. Every original tag is unchanged. The actual external fork PR Add XML 1.1 tags and EL functions to both taglibs #168's read-only/no-secrets run and the new workflow boundaries were inspected; the evidence documents the limit that a new external-fork CodeQL run was not manufactured. All final-main workflows passed: Java CI, packaged consumers, CodeQL, and dependency submission above. One PR ESAPI runner failed before tests with a Maven Central HTTP 403; its failed-job rerun passed.main. Removed merged batch 00/01/02 branches, the completed review branch, and disposable policy probes; retained unrelated branches and activegh-pages. Removed 25 obsolete shared Maven Actions caches (1,959,364,548 bytes); retained CodeQL cache and the user’s local Maven repository. Detailed validation, CI/security operations and recovery, and action provenance are checked in. Existing open PRs must refresh their old workflow tags before rerunning under the SHA policy. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 remains operationally incomplete; the full 1.5 backlog/release gate is unchanged. Next batch: 03, including the new OSGi PR Declare OSGi import ranges from actual API use and freeze bundle names #174 alongside Constrain OSGi imports to actual adapter API requirements and freeze bundle identities #137 and Add XML 1.1 tags and EL functions to both taglibs #131/PR Add XML 1.1 tags and EL functions to both taglibs #168.Batch 03 complete — 2026-09-25 (America/Los_Angeles)
28b57eb7d6cfb7b01dcbf7484da9d471e3ed1d3c, then merged normally as159041aa5a668483d456d3c9e8e4a673b697e6cbafter all 26 checks passed. Symbolic names are explicit and preserved, JSP/Jakarta core imports require[1.5,2)for JSON linkage, ESAPI uses the supported 1.4.1 security floor, and API ranges remain conservative. Real Felix R6/R8 consumers accept supported wiring and reject core 1.4.0; classpath/JPMS JSON linkage and 15 package guards pass. No embedded dependencies or new library/API baseline.ece754c3a094f591dc23213f317735f1b237b706, then merged normally as2b8e7b3a90895fbcacb89c3b2894c461dc71843dafter all 26 checks passed. Both adapters expose the three XML 1.1 contexts in advanced descriptors andforXml11in basic descriptors, with direct Writer delegation and context restrictions. The intendedforJavaomission remains explicit. Existing contract tests expand automatically; 34-file JSP/Jakarta parity passes.e6bbebe8e8ee9043e9cd1328fdda18b3e55816b2after all 26 checks passed on96a1c64d0878fedf6919d6cadb65e542a974986f. Normal Docker-freeverifynow forks isolated maintained Tomcat/Jasper 9.0.122 and 10.1.60 engines. The actual packaged TLDs generate 144 bindings across both adapters, 1,152 complete response-byte assertions, and 144 JSP translation rejections for bodies/missing attributes. Coverage includes JSON/XML 1.1, hostile markup/Unicode/controls, buffer boundaries, null/missing values and EL coercion. Engine dependencies stay outside library test/runtime classpaths. Local clean verify passed 2,178 unit plus eight existing integration tests, API/signatures and the new engines; CI retains the Java 8/11/17/21/25 matrix and browser checks.111d03390b96bba9fce33474cef413f8b07b6288after all 26 checks passed ond215dc02f275d8cd9914fbaf6dd50cb8197e9446. Explicit decision: retain the required actual-browser suite because facade byte comparisons cannot replace its DOM, HTML parser and JavaScript grammar assertions. The optional fixture now uses supported Boot 4.1.1, coherent Tomcat 11.0.26 APIs, Testcontainers 2.0.5 and aligned Selenium 4.49.0; library support baselines remain unchanged. Browser/helper images are pinned by verified registry index digest, discarded recording is disabled, and browser/container/server cleanup is explicit. The executable WAR itself is launched and its packaged JSP/JSTL views and exact encoded cells are verified. Removed unused JSON/service/test scaffolding and duplicate API JARs while retaining required JSTL. The 34 packaged third-party coordinates returned no OSV advisories at review time; this does not cover OS images, build plugins or test-only dependencies.session=falsefixed the startup assertion and the packaged test passed. Sol found no remaining actionable issues. Astra's final complete-diff review at413177cefound no actionable correctness/security findings and independently passed 10 policy/parser tests, 15 artifact guards, parity, and exact WAR/JAR comparison. CI then exposed Testcontainers image-name compatibility handling; an explicit declaration retained the exact digest, and Astra reviewed the correction throughd215dc02with no findings. AI review is not recorded as independent maintainer approval. Jim explicitly directed review and merge; Test every packaged taglib binding through real JSP engines #179 and Retain and modernize required browser and packaged WAR coverage #180 used the documented PR-only review bypass, while required CI/security checks have no bypass and passed.main; removed the merged task/review branches and retained contributor fork branches, active Pages and unrelated work. The open automated dependency PRs remain for deliberate review in their owning batches. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 and the full 1.5 release gate remain unchanged. Continue with batch 04 as directed.Batch 04 — implementation merged; historical-key evidence gap remains
3c82455fd02cf709f00b29f45c34d90f22a80d8f: source descriptors/attachment guards, text/XML normalization and safe ESAPI fixture cleanup. Sol then Astra found no actionable issues; all 26 final-head checks and all four post-merge main workflows passed.58af3881e5f6e2b58b10b5254809a02dde79a20a: Site/OSS-parent retirement, verified Maven wrapper and coherent plugin/build policy, source checks, measured coverage gates, isolated signing/publishing tools, deterministic artifacts and verified local bundle assembly. Existing Pages and published consumer identities/scopes remain intact.8d761d5c886455830dde0fc4600fc3747ddd5350: Docker/browser/WAR, ten ESAPI versions, Windows/Unix bootstrap with bad-hash rejection, Java 8 unit JVM, original-JAR consumers on 8/11/17/21/25, and CodeQL. Full local verify, 17 artifact guards, parity, coverage regression/skip probes and Java 17 packaged consumers also passed.VERIFYING.md. It remains open only for independent authorization records for the four earliest fingerprints; see the evidence-gap comment. Current project key unchanged.BUILDING.md,RELEASING.md, and batch 04 validation.3bd86250a9c9cd48577c3bf7fb9c46dbe91c1c90at 2026-09-26 07:35:25 UTC. Bouncy Castle pg/prov/util are aligned at 1.86 and both release plugins use compatible Plexus Utils 3.6.2, confined to plugin dependencies. All 28 final-head checks passed on0cb11a6a3bf2c842793c135df62fb9e9eaf2fd64; Sol and then Astra independently reviewed the diff and validation evidence with no actionable findings. The authorized PR-only review bypass was used; required CI/security checks have no bypass and passed. Model review is not independent maintainer approval.3bd8625: Java CI, packaged consumers, CodeQL, and dependency submission. Live SBOM readback confirms BC 1.86/Plexus 3.6.2 and Central 0.11.0 alongside runtime/test ESAPI 2.7.0.0 and Jasper 9.0.122/10.1.60/11.0.26; the release and runtime graphs coexist.main; all merged task branches, generated targets/bytecode caches, isolated Maven/wrapper repositories and downloaded reference JDK were removed. Disposable signing private material was deleted, compact validation evidence retained, and unrelated branches/Pages/user Maven storage preserved. Eight batch 04 issues are closed; Complete historical release-key records and verify consumer instructions #110 remains open for its four historical authorization-record gaps. Complete release readiness: Central 1.4.1 publication and independent maintainer recovery #111 retains Central access, independent custody and real validated-and-dropped staging rehearsals. The 1.5 release gate remains in force; no tagging/publication was authorized by this maintenance batch.