Modernize build policy and verify release artifacts - #185
Merged
Merged
Conversation
5 tasks
This was referenced Sep 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The build inherited an obsolete OSS parent and dormant Site/report stack, had no shared tool/plugin policy, and collected coverage without enforcing it. This change replaces those paths with a verified Maven wrapper, explicit lifecycle pins, build-bound source/coverage checks, and isolated release tooling.
oss-parent:9; preserve unique usage examples, attached source/Javadoc artifacts, public Pages and consumer identities/scopes.autoPublish=false, and optional WAR exclusion. A local assembler verifies all 17 signatures against an expected full fingerprint before creating the 102-entry bundle; it never uploads.Validation: full reference-JDK verify (2,178 unit tests, eight existing integration tests, both packaged JSP engines), 17 artifact guards, parity, and Java 17 isolated consumers passed. Real lost test coverage was rejected; coverage-skipped verify passed. All 17 unsigned artifacts from two fresh builds of
8b548244233330872ba2c6d165f7624b5e6cddffwere byte-identical. Isolated signing with a disposable test key produced 17 verified signatures; bundle verification, tamper/wrong-key/stale-POM probes, and noninteractive missing-key/SNAPSHOT release failures passed. Four optimized-mode regression tests protect against Python removing acceptance checks; all 14 policy/verification tests pass.All 28 checks passed at the initial implementation head, including Windows/Unix wrapper, browser/WAR, ten ESAPI versions, Java 8 unit JVM and original-JAR runtimes 8/11/17/21/25. Sol final review and Astra final pass found no remaining actionable findings on
8d761d5c886455830dde0fc4600fc3747ddd5350. Astra independently reran all 14 policy/verification tests, compared the 17 retained artifact hashes and verified both wrapper scripts against the upstream archive. All 28 checks passed on that final head before merge. Sol found the optimization-sensitive assertions and an inaccurate migrated Central example; both were fixed. AI review is not independent maintainer approval. Detailed evidence and limitations:releases/batch-04-validation.md.Central 0.11.0's
skipPublishingfilters artifacts instead of producing the ZIP suggested by upstream docs; the verified local assembler handles this explicitly. No production key/token, upload, release tag or 1.5 publication was used. #111 retains namespace access, independent custody and the real validated-and-dropped staging rehearsal.Closes #96. Closes #104. Closes #122. Closes #95. Closes #124. Closes #125. Closes #103.
Progresses #110 and batch 04 of #169.