Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 10 additions & 4 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Released entries are grounded in the linked immutable tags, GitHub release notes
and retained README announcements. Dates below are GitHub publication dates in
UTC where a release record exists; older announcement/tag dates are labeled.
An open proposal is not a release. Historical tags, assets and signatures remain
unchanged. [1.4.1 publication is pending on Central](releases/1.4.1.md).
unchanged. [1.4.1 is also available from Central](releases/1.4.1-central-publication.md).

## Unreleased — 1.5.0

Expand Down Expand Up @@ -40,7 +40,9 @@ Development builds use `1.5.0-SNAPSHOT`; this is not a published release.
(#185, #187). This does not change the Java 8 library runtime baseline.
- Add release verification, historical key evidence, maintainer custody and
release-specific ESAPI guidance (#164, #171, #185). Historical signing-key
authorization gaps (#110) and Central access/custody work (#111) remain open.
authorization gaps (#110) remain open. Central publication and the reported
completion of maintainer access/custody work (#111) are recorded in the
[publication follow-up](releases/1.4.1-central-publication.md).

These items are merged through `3bd86250a9c9cd48577c3bf7fb9c46dbe91c1c90`.
The [maintenance tracker](https://github.com/OWASP/owasp-java-encoder/issues/169)
Expand All @@ -50,8 +52,10 @@ records PRs, tests and dispositions; it is not approval to publish 1.5.

[Signed GitHub release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1)
([tag created 2026-09-25 in America/Los_Angeles](https://github.com/OWASP/owasp-java-encoder/tree/v1.4.1)).
**Central publication remains pending. Upgrade all four Java Encoder artifacts;
**Available from Maven Central. Upgrade all four Java Encoder artifacts;
versions through 1.4.0 are affected.**
Central publication was verified on 2026-09-27 UTC (2026-09-26 in
America/Los_Angeles); [all artifacts and signatures match the retained release](releases/1.4.1-central-publication.md).

- Fix `EncodedWriter` context corruption during buffer overflow
([GHSA-57jg-769q-93vh](https://github.com/OWASP/owasp-java-encoder/security/advisories/GHSA-57jg-769q-93vh)).
Expand Down Expand Up @@ -132,4 +136,6 @@ between `Version 1.2.3` and `v...`, and 1.4.1 identifies itself as a security
release. Keep those titles, dates and original text: they are unambiguous, and
backfilling older entries would require inventing publication timestamps. This
changelog supplies consistent navigation without rewriting history. Preserve
1.4.0's dated upgrade supplement and 1.4.1's security/pending-publication notice.
1.4.0's dated upgrade supplement and 1.4.1's security notice. The 1.4.1
pending-publication notice was replaced after Central publication and exact
artifact verification on 2026-09-27 UTC.
28 changes: 28 additions & 0 deletions MAINTAINERS.md
Original file line number Diff line number Diff line change
Expand Up @@ -170,3 +170,31 @@ publishing evidence. [#111](https://github.com/OWASP/owasp-java-encoder/issues/1
owns the remaining independent vault recovery, namespace access, publication,
and staging checks. [#95](https://github.com/OWASP/owasp-java-encoder/issues/95)
owns future release-tooling changes.

### Central publication follow-up: 2026-09-26 (America/Los_Angeles)

Jim's signed-in Portal account now shows the verified `org.owasp.encoder`
namespace in the Owasp organization. The exact retained signed 1.4.1 bundle was
validated and published as deployment `ce91e36f-756c-489f-bbea-3629b728ad28`.
All 17 POM/JAR files and their 17 signatures downloaded from Central matched
the retained release byte for byte. See the [publication record](releases/1.4.1-central-publication.md).

This supersedes the earlier namespace-access and pending-publication status
for Jim and 1.4.1.

Jim also confirmed on 2026-09-26 (America/Los_Angeles) that he and Jeremy both
completed the independent vault-recovery drills, namespace-access checks, and
separate validated-and-dropped Central staging rehearsals that day. This is
maintainer-reported completion; the individual private recovery records and
rehearsal deployment IDs were not supplied or independently inspected in this
publication session. Keep those operational records in each custodian's vault.

| Custodian | Independent vault-recovery drill | Namespace access | Separate validated-and-dropped rehearsal |
| --- | --- | --- | --- |
| Jim Manico | Completed 2026-09-26, reported by Jim | Verified directly by 1.4.1 publication | Completed 2026-09-26, reported by Jim |
| Jeremy Long | Completed 2026-09-26, reported by Jim | Confirmed 2026-09-26, reported by Jim | Completed 2026-09-26, reported by Jim |

Together with the publication verification and reconciled consumer notices,
this records completion of #111 on the stated evidence. The earlier dated
records remain as history. Future recovery drills and release rehearsals still
follow the procedures above; the 1.5 release gate remains unchanged.
11 changes: 5 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,19 +11,18 @@ safe templates, URL validation and other application controls.

**Upgrade all Java Encoder artifacts to 1.4.1. Versions through 1.4.0 are affected
by the [security issues fixed in 1.4.1](releases/1.4.1.md#security-fixes).**
Maven Central publication is still pending (checked 2026-09-26); the signed
[GitHub 1.4.1 release][release] is available. Download, [verify](VERIFYING.md) and
[install its retained artifacts](releases/1.4.1.md#verification) in your local or
organizational Maven repository. Central alone cannot resolve 1.4.1. Do not use
Central's affected 1.4.0 just because it is the latest version shown there.
Version 1.4.1 is available from [Maven Central](https://repo.maven.apache.org/maven2/org/owasp/encoder/)
and the signed [GitHub release][release]. All published artifacts and signatures
[match the retained release](releases/1.4.1-central-publication.md). See
[VERIFYING.md](VERIFYING.md) for verification instructions.

`main` is **unreleased 1.5.0-SNAPSHOT**. Its JSON API, JavaScript template support,
XML 1.1 tag bindings and ESAPI URL change are described below with version labels;
they are not features of the signed 1.4.1 release. See [CHANGELOG.md](CHANGELOG.md).

## Start using the OWASP Java Encoders

After installing the verified 1.4.1 artifacts, select the dependency you need.
Select the dependency you need; Maven resolves version 1.4.1 from Central.
All four use group ID `org.owasp.encoder` and version `1.4.1`:

| Artifact ID | Purpose and runtime dependencies |
Expand Down
21 changes: 12 additions & 9 deletions RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,9 @@ or verification for every item. Completing a maintenance batch does not satisfy
this gate on its own. Keep 1.5 development at `1.5.0-SNAPSHOT`; snapshot version
changes and reviewed maintenance merges are not release approval.

The pending Central publication of the already signed 1.4.1 release is separate:
when access is available, publish the retained exact signed bundle and verify
the published artifacts. Do not rebuild or replace 1.4.1 artifacts or move its tag.
The signed 1.4.1 release has been [published to Central and verified](releases/1.4.1-central-publication.md).
That publication is separate from the 1.5 release gate. Do not rebuild or replace
1.4.1 artifacts, republish its coordinates, or move its tag.

## Publishing access and project identity

Expand Down Expand Up @@ -158,9 +158,9 @@ uploading. Keep an audit record of the exact uploaded bundle and its SHA-256.
after its indexing delay.

If staging fails, repair the cause and drop the failed staging deployment before
retrying. For the pending 1.4.1 delivery, correct access or upload problems and
retry the retained exact bundle; do not rebuild or re-sign it to address a
validation failure. Escalate a failure requiring different artifact bytes to
retrying. For a retained signed release awaiting delivery, correct access or
upload problems and retry the exact bundle; do not rebuild or re-sign it to
address a validation failure. Escalate a failure requiring different artifact bytes to
the release coordinator. After publication, compare all four libraries' binary,
source, and Javadoc JARs and all five POMs and their signatures from Central with
the retained files and signed checksums. Only after that comparison succeeds,
Expand Down Expand Up @@ -218,9 +218,12 @@ annotations 2.22, HttpClient 5.6.4 and HttpCore/httpcore5-h2 5.4.4. The upstream
0.11.0 dependency versions matched current OSV advisories; these six reviewed
replacement coordinates did not on 2026-09-26. Local signed bundle validation
exercises the overridden plugin. This is not an audit of every plugin dependency
or a claim that the live Central HTTP path has been tested. Namespace access and
a validated-then-dropped rehearsal remain tracked by #111. `autoPublish=false`
stays mandatory. The optional WAR is excluded and its install/deploy goals skip.
or a claim that the plugin's live Central HTTP path has been tested. Jim's Portal
namespace access and exact 1.4.1 publication are now [verified](releases/1.4.1-central-publication.md).
Jim reported both publishers' namespace checks and separate validated-then-dropped
rehearsals complete on 2026-09-26; see [the dated maintainer record](MAINTAINERS.md#central-publication-follow-up-2026-09-26-americalos_angeles).
`autoPublish=false` stays mandatory. The optional WAR is excluded and its
install/deploy goals skip.


The signing plugin also pins `bcpg-jdk18on`, `bcprov-jdk18on`, and
Expand Down
5 changes: 3 additions & 2 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,9 @@

## Supported Versions

**Maven Central publication is pending.** Version 1.4.1 is available as signed
artifacts from the [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1).
Version **1.4.1** is available from [Maven Central](https://repo.maven.apache.org/maven2/org/owasp/encoder/)
and as signed artifacts from the [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1).
The Central artifacts and signatures [match the retained release](releases/1.4.1-central-publication.md).

Only the latest 1.x release receives security fixes. Fixes ship in a new release;
older release lines are not patched.
Expand Down
3 changes: 2 additions & 1 deletion VERIFYING.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,8 @@ the fingerprint before use. Never import private key material to verify a releas

For 1.4.1 and later releases until a documented rotation, the expected project key
is `1C5F632B86809F2F5DB25092BEA0075F94074A9B`. The [1.4.1 release instructions](releases/1.4.1.md#verification)
cover its signed GitHub assets while Central publication remains pending.
cover its signed GitHub assets. The [Central publication verification](releases/1.4.1-central-publication.md)
confirms that Central serves the same artifacts and signatures.

## Fresh public-only keyring

Expand Down
11 changes: 5 additions & 6 deletions esapi/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ The ESAPI dependency depends on the `encoder-esapi` release you consume:
| Adapter version | ESAPI dependency in its POM | Availability |
| --- | --- | --- |
| `1.4.0` | Maven range `[2.5.1.0,3)`; resolution can change and can select a release candidate | Maven Central; affected by Java Encoder's 1.4.1 security advisories |
| `1.4.1` | Fixed default `2.7.0.0` | [Signed GitHub security release][encoder-release]; Central publication is pending |
| `1.4.1` | Fixed default `2.7.0.0` | Maven Central and [signed GitHub security release][encoder-release] |
| `1.5.0-SNAPSHOT` | Fixed default `2.7.0.0` | Unreleased development; not a published release |

The fixed dependency was introduced in 1.4.1. It does not change the POM already
Expand All @@ -17,11 +17,10 @@ establish upstream security support.
## Upgrade to 1.4.1

Upgrade **all OWASP Java Encoder dependencies to 1.4.1**, including the core
`encoder` if your application declares or manages it separately. While Central
publication is pending, obtain the [signed 1.4.1 artifacts][encoder-release],
follow the [verification and local installation instructions][encoder-verification],
and install the retained POMs and JARs in your local or organizational Maven
repository. Version 1.4.1 will not resolve from Central alone.
`encoder` if your application declares or manages it separately. Version 1.4.1
resolves from Maven Central. The [signed GitHub artifacts][encoder-release]
remain available with [verification instructions][encoder-verification].
All Central artifacts and signatures [match the retained release](../releases/1.4.1-central-publication.md).

```xml
<dependency>
Expand Down
51 changes: 51 additions & 0 deletions releases/1.4.1-central-publication.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# OWASP Java Encoder 1.4.1 Central publication

Published on **2026-09-27 UTC** (2026-09-26 in America/Los_Angeles).
Central Portal reported **PUBLISHED** for deployment
`ce91e36f-756c-489f-bbea-3629b728ad28`, published by Jim Manico using the
verified `org.owasp.encoder` namespace in the Owasp organization.

The original retained [GitHub release bundle](https://github.com/OWASP/owasp-java-encoder/releases/download/v1.4.1/owasp-java-encoder-1.4.1-central-bundle.zip)
was uploaded without rebuilding, re-signing, or changing the release tag:

- Bundle SHA-256: `c70234d2290fff0011d484219b7bc8fae2581cf24b24b03abf5eab4413b6d4c3`.
- Source commit: `ab76d586bbfa4f138993d5dc3e9c4b3ea0dc7dce` (`v1.4.1`).
- Project signing fingerprint: `1C5F632B86809F2F5DB25092BEA0075F94074A9B`.

## Verification

Before upload, a fresh public-only GnuPG keyring verified all 19 signatures:
the 17 POM/JAR signatures and both signed checksum manifests. Every SHA-256
and SHA-512 manifest entry matched its original GitHub asset. All 102 bundle
entries were checked: 17 POMs/JARs, their 17 signatures, and 68 MD5/SHA-1/
SHA-256/SHA-512 checksums. The signed tag also verified with the project key.

Central validated every component before the Publish action. After publication,
all 12 binary/source/Javadoc JARs, five POMs, and their 17 signatures were
downloaded directly from `https://repo.maven.apache.org/maven2/`. All **34 files
matched the retained signed bundle byte for byte** at 04:44:17 UTC, which also
establishes agreement with the previously verified signatures and signed checksums.

| Artifact | Published files |
| --- | --- |
| `encoder` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.4.1/) |
| `encoder-jsp` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-jsp/1.4.1/) |
| `encoder-jakarta-jsp` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-jakarta-jsp/1.4.1/) |
| `encoder-esapi` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-esapi/1.4.1/) |
| `encoder-parent` | [1.4.1](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder-parent/1.4.1/) |

## Follow-up scope

The OWASP project page already references 1.4.1 and its signed GitHub downloads.
Javadoc's index still showed 1.4.0 immediately after publication; indexing is
separate from Central artifact availability. The GitHub release notice now
confirms Central availability and links all five published coordinates.
This publication directly establishes Jim's Portal namespace access and delivery
of 1.4.1. Separately, Jim confirmed that both he and Jeremy completed their
independent vault-recovery drills, namespace-access checks, and separate
validated-and-dropped staging rehearsals on 2026-09-26 (America/Los_Angeles).
The [maintainer record](../MAINTAINERS.md#central-publication-follow-up-2026-09-26-americalos_angeles)
distinguishes that reported completion from the direct publication verification;
individual recovery records and rehearsal deployment IDs were not inspected.
These results address [#111](https://github.com/OWASP/owasp-java-encoder/issues/111).
The 1.5 release gate remains unchanged.
18 changes: 11 additions & 7 deletions releases/1.4.1.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
# OWASP Java Encoder 1.4.1

**Maven Central publication is pending.** Version 1.4.1 is available as signed
artifacts from the [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1).
Until Central publication completes, download and verify those artifacts and
install them in your local or organizational Maven repository; version 1.4.1 will not resolve from Central alone. Maven Central 1.4.0 remains affected.
**Version 1.4.1 is available from Maven Central.** The Central artifacts and
signatures [match the retained signed release](1.4.1-central-publication.md),
verified on 2026-09-27 UTC (2026-09-26 in America/Los_Angeles).
The original [GitHub security release](https://github.com/OWASP/owasp-java-encoder/releases/tag/v1.4.1)
remains available. Versions through 1.4.0 remain affected.

## Security fixes

Expand Down Expand Up @@ -78,10 +79,13 @@ Run these checks in a directory containing all assets downloaded from the
release, and stop if any check fails. Require each signature to match the full
project fingerprint above; a successful signature from another key is not enough.

### Install verified artifacts while Central is pending
<a id="install-verified-artifacts-while-central-is-pending"></a>

From that verified asset directory, install the retained parent POM first and
then the four libraries with their original POMs. Maven must be available; these
### Optional local installation of verified artifacts

Maven can now resolve 1.4.1 directly from Central. For an optional local
installation from the verified asset directory, install the retained parent POM
first and then the four libraries with their original POMs. Maven must be available; these
commands download the install plugin and any external dependencies from Central.
They install existing release files without rebuilding or signing them:

Expand Down
Loading