From 0f88dba978cf70b70942793743f4ffb0d440698f Mon Sep 17 00:00:00 2001 From: Jim Manico Date: Sat, 26 Sep 2026 21:49:32 -0700 Subject: [PATCH 1/2] docs: record verified 1.4.1 Maven Central publication --- CHANGELOG.md | 10 ++++-- MAINTAINERS.md | 13 ++++++++ README.md | 11 +++---- RELEASING.md | 17 +++++----- SECURITY.md | 5 +-- VERIFYING.md | 3 +- esapi/README.md | 11 +++---- releases/1.4.1-central-publication.md | 47 +++++++++++++++++++++++++++ releases/1.4.1.md | 18 ++++++---- 9 files changed, 102 insertions(+), 33 deletions(-) create mode 100644 releases/1.4.1-central-publication.md diff --git a/CHANGELOG.md b/CHANGELOG.md index b20fda6..94b64d2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,7 @@ Released entries are grounded in the linked immutable tags, GitHub release notes and retained README announcements. Dates below are GitHub publication dates in UTC where a release record exists; older announcement/tag dates are labeled. An open proposal is not a release. Historical tags, assets and signatures remain -unchanged. [1.4.1 publication is pending on Central](releases/1.4.1.md). +unchanged. [1.4.1 is also available from Central](releases/1.4.1-central-publication.md). ## Unreleased — 1.5.0 @@ -50,8 +50,10 @@ records PRs, tests and dispositions; it is not approval to publish 1.5. [Signed GitHub release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1) ([tag created 2026-09-25 in America/Los_Angeles](https://github.com/OWASP/owasp-java-encoder/tree/v1.4.1)). -**Central publication remains pending. Upgrade all four Java Encoder artifacts; +**Available from Maven Central. Upgrade all four Java Encoder artifacts; versions through 1.4.0 are affected.** +Central publication was verified on 2026-09-27 UTC (2026-09-26 in +America/Los_Angeles); [all artifacts and signatures match the retained release](releases/1.4.1-central-publication.md). - Fix `EncodedWriter` context corruption during buffer overflow ([GHSA-57jg-769q-93vh](https://github.com/OWASP/owasp-java-encoder/security/advisories/GHSA-57jg-769q-93vh)). @@ -132,4 +134,6 @@ between `Version 1.2.3` and `v...`, and 1.4.1 identifies itself as a security release. Keep those titles, dates and original text: they are unambiguous, and backfilling older entries would require inventing publication timestamps. This changelog supplies consistent navigation without rewriting history. Preserve -1.4.0's dated upgrade supplement and 1.4.1's security/pending-publication notice. +1.4.0's dated upgrade supplement and 1.4.1's security notice. The 1.4.1 +pending-publication notice was replaced after Central publication and exact +artifact verification on 2026-09-27 UTC. diff --git a/MAINTAINERS.md b/MAINTAINERS.md index 3c33a39..a12e1f7 100644 --- a/MAINTAINERS.md +++ b/MAINTAINERS.md @@ -170,3 +170,16 @@ publishing evidence. [#111](https://github.com/OWASP/owasp-java-encoder/issues/1 owns the remaining independent vault recovery, namespace access, publication, and staging checks. [#95](https://github.com/OWASP/owasp-java-encoder/issues/95) owns future release-tooling changes. + +### Central publication follow-up: 2026-09-26 (America/Los_Angeles) + +Jim's signed-in Portal account now shows the verified `org.owasp.encoder` +namespace in the Owasp organization. The exact retained signed 1.4.1 bundle was +validated and published as deployment `ce91e36f-756c-489f-bbea-3629b728ad28`. +All 17 POM/JAR files and their 17 signatures downloaded from Central matched +the retained release byte for byte. See the [publication record](releases/1.4.1-central-publication.md). + +This supersedes the earlier namespace-access and pending-publication status +for Jim and 1.4.1. The independent vault imports/recovery drills, Jeremy's +current access, and both distinct validated-and-dropped staging rehearsals +remain unconfirmed. Keep #111 open for those remaining checks. diff --git a/README.md b/README.md index 921f55a..589f87e 100644 --- a/README.md +++ b/README.md @@ -11,11 +11,10 @@ safe templates, URL validation and other application controls. **Upgrade all Java Encoder artifacts to 1.4.1. Versions through 1.4.0 are affected by the [security issues fixed in 1.4.1](releases/1.4.1.md#security-fixes).** -Maven Central publication is still pending (checked 2026-09-26); the signed -[GitHub 1.4.1 release][release] is available. Download, [verify](VERIFYING.md) and -[install its retained artifacts](releases/1.4.1.md#verification) in your local or -organizational Maven repository. Central alone cannot resolve 1.4.1. Do not use -Central's affected 1.4.0 just because it is the latest version shown there. +Version 1.4.1 is available from [Maven Central](https://repo.maven.apache.org/maven2/org/owasp/encoder/) +and the signed [GitHub release][release]. All published artifacts and signatures +[match the retained release](releases/1.4.1-central-publication.md). See +[VERIFYING.md](VERIFYING.md) for verification instructions. `main` is **unreleased 1.5.0-SNAPSHOT**. Its JSON API, JavaScript template support, XML 1.1 tag bindings and ESAPI URL change are described below with version labels; @@ -23,7 +22,7 @@ they are not features of the signed 1.4.1 release. See [CHANGELOG.md](CHANGELOG. ## Start using the OWASP Java Encoders -After installing the verified 1.4.1 artifacts, select the dependency you need. +Select the dependency you need; Maven resolves version 1.4.1 from Central. All four use group ID `org.owasp.encoder` and version `1.4.1`: | Artifact ID | Purpose and runtime dependencies | diff --git a/RELEASING.md b/RELEASING.md index e9d0cd8..c21ec0c 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -9,9 +9,9 @@ or verification for every item. Completing a maintenance batch does not satisfy this gate on its own. Keep 1.5 development at `1.5.0-SNAPSHOT`; snapshot version changes and reviewed maintenance merges are not release approval. -The pending Central publication of the already signed 1.4.1 release is separate: -when access is available, publish the retained exact signed bundle and verify -the published artifacts. Do not rebuild or replace 1.4.1 artifacts or move its tag. +The signed 1.4.1 release has been [published to Central and verified](releases/1.4.1-central-publication.md). +That publication is separate from the 1.5 release gate. Do not rebuild or replace +1.4.1 artifacts, republish its coordinates, or move its tag. ## Publishing access and project identity @@ -158,9 +158,9 @@ uploading. Keep an audit record of the exact uploaded bundle and its SHA-256. after its indexing delay. If staging fails, repair the cause and drop the failed staging deployment before -retrying. For the pending 1.4.1 delivery, correct access or upload problems and -retry the retained exact bundle; do not rebuild or re-sign it to address a -validation failure. Escalate a failure requiring different artifact bytes to +retrying. For a retained signed release awaiting delivery, correct access or +upload problems and retry the exact bundle; do not rebuild or re-sign it to +address a validation failure. Escalate a failure requiring different artifact bytes to the release coordinator. After publication, compare all four libraries' binary, source, and Javadoc JARs and all five POMs and their signatures from Central with the retained files and signed checksums. Only after that comparison succeeds, @@ -218,8 +218,9 @@ annotations 2.22, HttpClient 5.6.4 and HttpCore/httpcore5-h2 5.4.4. The upstream 0.11.0 dependency versions matched current OSV advisories; these six reviewed replacement coordinates did not on 2026-09-26. Local signed bundle validation exercises the overridden plugin. This is not an audit of every plugin dependency -or a claim that the live Central HTTP path has been tested. Namespace access and -a validated-then-dropped rehearsal remain tracked by #111. `autoPublish=false` +or a claim that the plugin's live Central HTTP path has been tested. Jim's Portal +namespace access and exact 1.4.1 publication are now [verified](releases/1.4.1-central-publication.md); +a validated-then-dropped rehearsal and Jeremy's access remain tracked by #111. `autoPublish=false` stays mandatory. The optional WAR is excluded and its install/deploy goals skip. diff --git a/SECURITY.md b/SECURITY.md index a59d1c3..ffaa227 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,8 +2,9 @@ ## Supported Versions -**Maven Central publication is pending.** Version 1.4.1 is available as signed -artifacts from the [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1). +Version **1.4.1** is available from [Maven Central](https://repo.maven.apache.org/maven2/org/owasp/encoder/) +and as signed artifacts from the [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1). +The Central artifacts and signatures [match the retained release](releases/1.4.1-central-publication.md). Only the latest 1.x release receives security fixes. Fixes ship in a new release; older release lines are not patched. diff --git a/VERIFYING.md b/VERIFYING.md index fec330e..949def9 100644 --- a/VERIFYING.md +++ b/VERIFYING.md @@ -7,7 +7,8 @@ the fingerprint before use. Never import private key material to verify a releas For 1.4.1 and later releases until a documented rotation, the expected project key is `1C5F632B86809F2F5DB25092BEA0075F94074A9B`. The [1.4.1 release instructions](releases/1.4.1.md#verification) -cover its signed GitHub assets while Central publication remains pending. +cover its signed GitHub assets. The [Central publication verification](releases/1.4.1-central-publication.md) +confirms that Central serves the same artifacts and signatures. ## Fresh public-only keyring diff --git a/esapi/README.md b/esapi/README.md index 5f26c42..6d6613b 100644 --- a/esapi/README.md +++ b/esapi/README.md @@ -5,7 +5,7 @@ The ESAPI dependency depends on the `encoder-esapi` release you consume: | Adapter version | ESAPI dependency in its POM | Availability | | --- | --- | --- | | `1.4.0` | Maven range `[2.5.1.0,3)`; resolution can change and can select a release candidate | Maven Central; affected by Java Encoder's 1.4.1 security advisories | -| `1.4.1` | Fixed default `2.7.0.0` | [Signed GitHub security release][encoder-release]; Central publication is pending | +| `1.4.1` | Fixed default `2.7.0.0` | Maven Central and [signed GitHub security release][encoder-release] | | `1.5.0-SNAPSHOT` | Fixed default `2.7.0.0` | Unreleased development; not a published release | The fixed dependency was introduced in 1.4.1. It does not change the POM already @@ -17,11 +17,10 @@ establish upstream security support. ## Upgrade to 1.4.1 Upgrade **all OWASP Java Encoder dependencies to 1.4.1**, including the core -`encoder` if your application declares or manages it separately. While Central -publication is pending, obtain the [signed 1.4.1 artifacts][encoder-release], -follow the [verification and local installation instructions][encoder-verification], -and install the retained POMs and JARs in your local or organizational Maven -repository. Version 1.4.1 will not resolve from Central alone. +`encoder` if your application declares or manages it separately. Version 1.4.1 +resolves from Maven Central. The [signed GitHub artifacts][encoder-release] +remain available with [verification instructions][encoder-verification]. +All Central artifacts and signatures [match the retained release](../releases/1.4.1-central-publication.md). ```xml diff --git a/releases/1.4.1-central-publication.md b/releases/1.4.1-central-publication.md new file mode 100644 index 0000000..837f0b6 --- /dev/null +++ b/releases/1.4.1-central-publication.md @@ -0,0 +1,47 @@ +# OWASP Java Encoder 1.4.1 Central publication + +Published on **2026-09-27 UTC** (2026-09-26 in America/Los_Angeles). +Central Portal reported **PUBLISHED** for deployment +`ce91e36f-756c-489f-bbea-3629b728ad28`, published by Jim Manico using the +verified `org.owasp.encoder` namespace in the Owasp organization. + +The original retained [GitHub release bundle](https://github.com/OWASP/owasp-java-encoder/releases/download/v1.4.1/owasp-java-encoder-1.4.1-central-bundle.zip) +was uploaded without rebuilding, re-signing, or changing the release tag: + +- Bundle SHA-256: `c70234d2290fff0011d484219b7bc8fae2581cf24b24b03abf5eab4413b6d4c3`. +- Source commit: `ab76d586bbfa4f138993d5dc3e9c4b3ea0dc7dce` (`v1.4.1`). +- Project signing fingerprint: `1C5F632B86809F2F5DB25092BEA0075F94074A9B`. + +## Verification + +Before upload, a fresh public-only GnuPG keyring verified all 19 signatures: +the 17 POM/JAR signatures and both signed checksum manifests. Every SHA-256 +and SHA-512 manifest entry matched its original GitHub asset. All 102 bundle +entries were checked: 17 POMs/JARs, their 17 signatures, and 68 MD5/SHA-1/ +SHA-256/SHA-512 checksums. The signed tag also verified with the project key. + +Central validated every component before the Publish action. After publication, +all 12 binary/source/Javadoc JARs, five POMs, and their 17 signatures were +downloaded directly from `https://repo.maven.apache.org/maven2/`. All **34 files +matched the retained signed bundle byte for byte** at 04:44:17 UTC, which also +establishes agreement with the previously verified signatures and signed checksums. + +| Artifact | Published files | +| --- | --- | +| `encoder` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.4.1/) | +| `encoder-jsp` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-jsp/1.4.1/) | +| `encoder-jakarta-jsp` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-jakarta-jsp/1.4.1/) | +| `encoder-esapi` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-esapi/1.4.1/) | +| `encoder-parent` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-parent/1.4.1/) | + +## Follow-up scope + +The OWASP project page already references 1.4.1 and its signed GitHub downloads. +Javadoc's index still showed 1.4.0 immediately after publication; indexing is +separate from Central artifact availability. The GitHub release notice now +confirms Central availability and links all five published coordinates. +This publication establishes Jim's Portal namespace access and delivery of +1.4.1. It does not establish independent vault recovery, Jeremy's publishing +access, or either publisher's distinct validated-and-dropped rehearsal; those +remain tracked by [#111](https://github.com/OWASP/owasp-java-encoder/issues/111). +The 1.5 release gate remains unchanged. diff --git a/releases/1.4.1.md b/releases/1.4.1.md index 70e8ee1..9cf5586 100644 --- a/releases/1.4.1.md +++ b/releases/1.4.1.md @@ -1,9 +1,10 @@ # OWASP Java Encoder 1.4.1 -**Maven Central publication is pending.** Version 1.4.1 is available as signed -artifacts from the [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1). -Until Central publication completes, download and verify those artifacts and -install them in your local or organizational Maven repository; version 1.4.1 will not resolve from Central alone. Maven Central 1.4.0 remains affected. +**Version 1.4.1 is available from Maven Central.** The Central artifacts and +signatures [match the retained signed release](1.4.1-central-publication.md), +verified on 2026-09-27 UTC (2026-09-26 in America/Los_Angeles). +The original [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1) +remains available. Versions through 1.4.0 remain affected. ## Security fixes @@ -78,10 +79,13 @@ Run these checks in a directory containing all assets downloaded from the release, and stop if any check fails. Require each signature to match the full project fingerprint above; a successful signature from another key is not enough. -### Install verified artifacts while Central is pending + -From that verified asset directory, install the retained parent POM first and -then the four libraries with their original POMs. Maven must be available; these +### Optional local installation of verified artifacts + +Maven can now resolve 1.4.1 directly from Central. For an optional local +installation from the verified asset directory, install the retained parent POM +first and then the four libraries with their original POMs. Maven must be available; these commands download the install plugin and any external dependencies from Central. They install existing release files without rebuilding or signing them: From 3059735c6a655a1ddf9f591ce1c686243410d62a Mon Sep 17 00:00:00 2001 From: Jim Manico Date: Sat, 26 Sep 2026 21:51:33 -0700 Subject: [PATCH 2/2] docs: record maintainer confirmation of recovery and rehearsals --- CHANGELOG.md | 4 +++- MAINTAINERS.md | 21 ++++++++++++++++++--- RELEASING.md | 8 +++++--- releases/1.4.1-central-publication.md | 12 ++++++++---- 4 files changed, 34 insertions(+), 11 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 94b64d2..495ae2f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -40,7 +40,9 @@ Development builds use `1.5.0-SNAPSHOT`; this is not a published release. (#185, #187). This does not change the Java 8 library runtime baseline. - Add release verification, historical key evidence, maintainer custody and release-specific ESAPI guidance (#164, #171, #185). Historical signing-key - authorization gaps (#110) and Central access/custody work (#111) remain open. + authorization gaps (#110) remain open. Central publication and the reported + completion of maintainer access/custody work (#111) are recorded in the + [publication follow-up](releases/1.4.1-central-publication.md). These items are merged through `3bd86250a9c9cd48577c3bf7fb9c46dbe91c1c90`. The [maintenance tracker](https://github.com/OWASP/owasp-java-encoder/issues/169) diff --git a/MAINTAINERS.md b/MAINTAINERS.md index a12e1f7..f9dbc36 100644 --- a/MAINTAINERS.md +++ b/MAINTAINERS.md @@ -180,6 +180,21 @@ All 17 POM/JAR files and their 17 signatures downloaded from Central matched the retained release byte for byte. See the [publication record](releases/1.4.1-central-publication.md). This supersedes the earlier namespace-access and pending-publication status -for Jim and 1.4.1. The independent vault imports/recovery drills, Jeremy's -current access, and both distinct validated-and-dropped staging rehearsals -remain unconfirmed. Keep #111 open for those remaining checks. +for Jim and 1.4.1. + +Jim also confirmed on 2026-09-26 (America/Los_Angeles) that he and Jeremy both +completed the independent vault-recovery drills, namespace-access checks, and +separate validated-and-dropped Central staging rehearsals that day. This is +maintainer-reported completion; the individual private recovery records and +rehearsal deployment IDs were not supplied or independently inspected in this +publication session. Keep those operational records in each custodian's vault. + +| Custodian | Independent vault-recovery drill | Namespace access | Separate validated-and-dropped rehearsal | +| --- | --- | --- | --- | +| Jim Manico | Completed 2026-09-26, reported by Jim | Verified directly by 1.4.1 publication | Completed 2026-09-26, reported by Jim | +| Jeremy Long | Completed 2026-09-26, reported by Jim | Confirmed 2026-09-26, reported by Jim | Completed 2026-09-26, reported by Jim | + +Together with the publication verification and reconciled consumer notices, +this records completion of #111 on the stated evidence. The earlier dated +records remain as history. Future recovery drills and release rehearsals still +follow the procedures above; the 1.5 release gate remains unchanged. diff --git a/RELEASING.md b/RELEASING.md index c21ec0c..6d9d42a 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -219,9 +219,11 @@ annotations 2.22, HttpClient 5.6.4 and HttpCore/httpcore5-h2 5.4.4. The upstream replacement coordinates did not on 2026-09-26. Local signed bundle validation exercises the overridden plugin. This is not an audit of every plugin dependency or a claim that the plugin's live Central HTTP path has been tested. Jim's Portal -namespace access and exact 1.4.1 publication are now [verified](releases/1.4.1-central-publication.md); -a validated-then-dropped rehearsal and Jeremy's access remain tracked by #111. `autoPublish=false` -stays mandatory. The optional WAR is excluded and its install/deploy goals skip. +namespace access and exact 1.4.1 publication are now [verified](releases/1.4.1-central-publication.md). +Jim reported both publishers' namespace checks and separate validated-then-dropped +rehearsals complete on 2026-09-26; see [the dated maintainer record](MAINTAINERS.md#central-publication-follow-up-2026-09-26-americalos_angeles). +`autoPublish=false` stays mandatory. The optional WAR is excluded and its +install/deploy goals skip. The signing plugin also pins `bcpg-jdk18on`, `bcprov-jdk18on`, and diff --git a/releases/1.4.1-central-publication.md b/releases/1.4.1-central-publication.md index 837f0b6..e136b24 100644 --- a/releases/1.4.1-central-publication.md +++ b/releases/1.4.1-central-publication.md @@ -40,8 +40,12 @@ The OWASP project page already references 1.4.1 and its signed GitHub downloads. Javadoc's index still showed 1.4.0 immediately after publication; indexing is separate from Central artifact availability. The GitHub release notice now confirms Central availability and links all five published coordinates. -This publication establishes Jim's Portal namespace access and delivery of -1.4.1. It does not establish independent vault recovery, Jeremy's publishing -access, or either publisher's distinct validated-and-dropped rehearsal; those -remain tracked by [#111](https://github.com/OWASP/owasp-java-encoder/issues/111). +This publication directly establishes Jim's Portal namespace access and delivery +of 1.4.1. Separately, Jim confirmed that both he and Jeremy completed their +independent vault-recovery drills, namespace-access checks, and separate +validated-and-dropped staging rehearsals on 2026-09-26 (America/Los_Angeles). +The [maintainer record](../MAINTAINERS.md#central-publication-follow-up-2026-09-26-americalos_angeles) +distinguishes that reported completion from the direct publication verification; +individual recovery records and rehearsal deployment IDs were not inspected. +These results address [#111](https://github.com/OWASP/owasp-java-encoder/issues/111). The 1.5 release gate remains unchanged.