From fddfa4e8ef8163713e36d585522763c84ffc2fff Mon Sep 17 00:00:00 2001 From: Jim Manico Date: Sat, 26 Sep 2026 22:16:15 -0700 Subject: [PATCH] Complete historical key archive and maintenance closeout --- CHANGELOG.md | 12 +- KEYS | 94 ++++++++++ RELEASING.md | 9 +- VERIFYING.md | 53 +++--- releases/historical-key-authentication.md | 97 +++++++++++ releases/historical-key-evidence.json | 198 ++++++++++++++++++++++ releases/maintenance-closeout.md | 72 ++++++++ 7 files changed, 505 insertions(+), 30 deletions(-) create mode 100644 releases/historical-key-authentication.md create mode 100644 releases/historical-key-evidence.json create mode 100644 releases/maintenance-closeout.md diff --git a/CHANGELOG.md b/CHANGELOG.md index 495ae2f..d9de16d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -40,13 +40,15 @@ Development builds use `1.5.0-SNAPSHOT`; this is not a published release. (#185, #187). This does not change the Java 8 library runtime baseline. - Add release verification, historical key evidence, maintainer custody and release-specific ESAPI guidance (#164, #171, #185). Historical signing-key - authorization gaps (#110) remain open. Central publication and the reported - completion of maintainer access/custody work (#111) are recorded in the - [publication follow-up](releases/1.4.1-central-publication.md). + authorization records (#110) now distinguish retrospective maintainer + authentication from historical GitHub/project records; see the + [key verification record](releases/historical-key-authentication.md). + Central publication and the reported completion of maintainer access/custody + work (#111) are recorded in the [publication follow-up](releases/1.4.1-central-publication.md). -These items are merged through `3bd86250a9c9cd48577c3bf7fb9c46dbe91c1c90`. The [maintenance tracker](https://github.com/OWASP/owasp-java-encoder/issues/169) -records PRs, tests and dispositions; it is not approval to publish 1.5. +and [closeout record](releases/maintenance-closeout.md) record the corresponding +PRs, tests and dispositions; they are not approval to publish 1.5. ## 1.4.1 — 2026-09-26 UTC diff --git a/KEYS b/KEYS index b0196ca..6689dcf 100644 --- a/KEYS +++ b/KEYS @@ -74,6 +74,100 @@ These keys are archival, not authorized for new releases. See VERIFYING.md for observed version mapping, expiry and source authentication. The current project key above remains unchanged. +Versions: 1.1 +Fingerprint: 37D880CD406BAD34CA2A8DD61845EF37A3B6533A +Authentication record: Jim Manico, retrospective exact-fingerprint authentication, 2026-09-26; see releases/historical-key-authentication.md +Historical verification only; expired certificate, not authorized for new releases. + +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQGiBFCi/CIRBADETL2sotRoEJ9AGJ8t7CilrL/UnY5YH64rjRPUFr1wgH6RQlh/ +gCvyh2lrkPYQiKUvpxNK3WnC9IELPsVR6klFiR35G6WX+hCz3cjns1HsmxQ2+KGx +H1DSMKvzEko12skrlRF/2DOReb8qrG4d+rcW3efFDK69axgWiUIynMlOAwCg+bj3 +BJ0e3Je1C5VoSftUoBP8PdMD/ArO7Fg4cBh956ttVvLWmyq0JCoOqoOY51IrvIGq +ue7eYcUcoi6Cb4bKO/FbYTFsJ3BF9pfIRh0Fzutq/Z3CBhkwZUoMNNpGvQfO6aEz +AFy/5Ga5wmzWyVzd3rG+IgI9ZG+V0jEkZG7SOvEFh6ovKrcE1S7NHP75OOBd8/y9 +YKTlBACpai6AMaYdT8CT7ORTL2yuukx1Ud0GogoAyxhiecfIz7e8jtOtcOyaF9e0 +cTQ5jPOJFxM6ayo0+HjTcGIExgBpIPMrRjGiDxABogc/1PXcsKhEjb/IXL/cFJyB +2+m8a90Nfp+BsTfaM8ecJ9BzhGcOHWcxShyhCnc8O+WjH2tMYrQjSmVyZW15IExv +bmcgPGplcmVteS5sb25nQGdtYWlsLmNvbT6IZQQTEQIAJQUCUKL8IgIbAwUJAeEz +gAYLCQgHAwIEFQIIAwMWAgECHgECF4AACgkQGEXvN6O2Uzp1hwCg5NLgju3nWSc5 +vQfzbbcTMm2okSIAnjZejzmqZbZdX/MSuc1PIsMpLiVO +=JC0V +-----END PGP PUBLIC KEY BLOCK----- + +Versions: 1.1.1 +Fingerprint: AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2 +Authentication record: Jim Manico, retrospective exact-fingerprint authentication, 2026-09-26; see releases/historical-key-authentication.md +Historical verification only; expired certificate, not authorized for new releases. + +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQENBFKHhtkBCACbIO7v+Qlc9hojh9czoQlkrfxuArR6qB0bEyX06r+hInDCyG8L +P2RxiNSSpxM0LmE0+uCZvHnh7gKEfBAc6qa66Awulz3uBI3zHSenIHWynd9NhicY ++LaFrRmL83cvcgxzFNCwsbg1CPyE51aEEy5IMvjz6m/ZclTJhFH3sFy/bhQgYHsP +OdY7mSQ4M5L6wKvtAmXsT9OJpzelOprSa1S7rj5UrzHA/wfl9F3R8DQNU2A7eEXv +vOpBQ7NqOoChcVP1QBLS4/ukmUGHBTXi1hcAu7UZC5vbaq4ApMzOM9j0PLSGXvSU +gyib8H2oLM1dURmn/Agez8IdwvGtK0amDHARABEBAAG0I0plcmVteSBMb25nIDxq +ZXJlbXkubG9uZ0BnbWFpbC5jb20+iQE+BBMBAgAoBQJSh4bZAhsDBQkB4TOABgsJ +CAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRBa1vfIdA488rBVB/952SypkONVnvJx +fQ1rFEPDRGRWX4ElUmhomUxmUJaI0eUa+NL3hTwCrTxtb/HWVDh73pdiaaCTzdBP +9Oco3Nqn1ooCsRl4pv/maIJiM8Fo4q43QzrpWfXyKpO4Cj/vMKnlmZjKpJzlZCSo +TJYxfJcPihS+LYgf2qK0u+i8Gy1Zp9nwn6st2/bFerH4i+PoLqsLOlcPcN7zZF0L +1V3kndi3alX0DsuqZ8eqVYRoIgVO6FnfnnPZub0xXZruQ4yLu7uRbIzoxgTMu1mE +2LysciAmByR19Tg1NP0DfbeY0mhZZzMJgmXtgvGFY8004LIRS3A+NT4fezlUiVMN +4OzbVVpV +=HEeP +-----END PGP PUBLIC KEY BLOCK----- + +Versions: 1.2 +Fingerprint: C82AF58D3985677F9D575CEC9BC190E3DA071BD4 +Authentication record: Jim Manico, retrospective exact-fingerprint authentication, 2026-09-26; see releases/historical-key-authentication.md +Historical verification only; expired certificate, not authorized for new releases. + +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQENBFT1lyYBCADSHA1nMrkID9RWgJfiimLforeFYEEq3pliZpNrvMJVAdlruJP+ +DWyOy3EpxYa8eszbG92Btl4TlG2vtkH5zsv3vpwBKDShLds3+hTNAX9mXTSovJYP +iquLISkCrZ3BwY9ezKGTG2AsmJy8Uogy1TSnk9qJqO/fUHU00MO2YpkVAu7j6Cjo +Jgygy5T6Z35uQJIfmppcuTcfAbG82umcy+FjqftPGhO/hyh0KUQR3H6ovbuogPB4 +l8STH9ZA31JOYe46+HP6KJHWaIK/YM7DMKDBuSI6kzFQnUatO6yv88d2zNys3J2L +shGeZEh652FLUBJ5rmpMAIMJPzAREggnJNuFABEBAAG0I0plcmVteSBMb25nIDxq +ZXJlbXkubG9uZ0Bvd2FzcC5vcmc+iQE+BBMBAgAoAhsDBgsJCAcDAgYVCAIJCgsE +FgIDAQIeAQIXgAUCVtsARwUJA8acoQAKCRCbwZDj2gcb1JQpCAC1lpzyq3X7lLWx +wuhqeKgK9IzLxlnV7iek/XbWXaVwGwEhoOYpq7xzuGWNkpjvNCWJ9fXyIYDU4+tF +S9ssINrl0Acw3aDkt6/AkM7g4aC0OegHR6tNZV6YZYUnhhQwJQO+SwZ3+JfkPpB8 +oznZ0lo7QUVPcUjAV6/JABAwyZSnvNnlYGzIIGCFWrLnRREBd83UiqErZDZAm1W0 +qljqFJJaZUWm5jJ/GxKFBrFYW57s4W3Ih6PrS1TOpfX0LcsZJRMyirQ32VwOWmNF +l/3QUkepAbTyLesxHfLjqAbwekgC8AMs1dXE6RTHRbaIrHCn3ezGxKFZmn045+0R +4cW16KiG +=adbD +-----END PGP PUBLIC KEY BLOCK----- + +Versions: 1.2.1 +Fingerprint: 33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE +Authentication record: Jeremy Long's public GitHub GPG-key record 213069; see releases/historical-key-authentication.md +Historical verification only; expired certificate, not authorized for new releases. + +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQENBFcb4OEBCADKVrVQkQKlqTg4mB/jAoOxBYm3l5tNf4IY5N5hp7sj3HO5S4Vt +onWvN960K0W+MWUvBVydLaJDcEH1OJXkj58kGwDyBVQjUnnGBgJbs9TtMKyB89ew +a1W2OqnXvonFZ0bThpc6LceFV/HBWGIfzjutEPxJpgTQzyI5Ua2BYaLvHP4y6+QT +eQIF1fLqodSJxiejmoWdiLx5zkkSKnfRv5MKSYHlNkfu/Pa2JEm//oWEhljyI/R7 +6JmUWw7KaQIW0sjXVOwKnaQMT+ihQjevpvOE2UQMmyuC1kZGRiyfp+Oh3KOTg6Nr +T7UaII0F4vXOfmTeuD2WrxDBV71TXAJVROpFABEBAAG0I0plcmVteSBMb25nIDxq +ZXJlbXkubG9uZ0BnbWFpbC5jb20+iQE/BBMBCAApBQJXG+DhAhsDBQkB4TOABwsJ +CAcDAgEGFQgCCQoLBBYCAwECHgECF4AACgkQ9+uo7NbyK/65gwgAgXE+wo69vhS5 +DHs4aqcaLHcLcH+oiLitgMiRd/TQvX+iB9sVln2d2+yulo5auMrccSLhF+HAT4u6 +0IOFtKqfhZJA7ogtvwS4UOC6Zz3ZGk0VEalsaQWC6SAck8cCJlXJ6Z7Z61Tasfw8 +5m+N0LDoiqldHFGoTQaXGpnvMoLtMLO0g75xkTxHIi59YSRnEMJiKgMYv4+lznai +hMiAxqyGBHDyux2L7ypI6LYSKkzAVtfZXHJxwwzrXtpcqpqCUHqrFG02n+yvS9Vm +sm9AKdrlg0JSM/JmcUlD7UCCYVL21X1n2JHsvjOKszf1YjJ/msvrCa+GxtYhmP+5 +R66aTuxIsg== +=u974 +-----END PGP PUBLIC KEY BLOCK----- + Versions: 1.2.2-1.2.3 Fingerprint: F9514E84AE3708288374BBBE097586CFEA37F9A6 Authentication record: Jeremy Long's OWASP Dependency-Check v6.0.0 CLI verification guide (2020) diff --git a/RELEASING.md b/RELEASING.md index 6d9d42a..5ce1cf3 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -9,6 +9,11 @@ or verification for every item. Completing a maintenance batch does not satisfy this gate on its own. Keep 1.5 development at `1.5.0-SNAPSHOT`; snapshot version changes and reviewed maintenance merges are not release approval. +The [2026-09-26 maintenance closeout](releases/maintenance-closeout.md) records +the final backlog inventory and dispositions for #110 and #169. A closed tracker +does not waive this gate: repeat the complete open-issue/PR inventory when a 1.5 +release is actually proposed and obtain release approval then. + The signed 1.4.1 release has been [published to Central and verified](releases/1.4.1-central-publication.md). That publication is separate from the 1.5 release gate. Do not rebuild or replace 1.4.1 artifacts, republish its coordinates, or move its tag. @@ -16,8 +21,8 @@ That publication is separate from the 1.5 release gate. Do not rebuild or replac ## Publishing access and project identity See [MAINTAINERS.md](MAINTAINERS.md) for named maintainers, security contacts, -signing-key custodians, independent recovery procedures, and the dated status -of outstanding custody and publishing checks. +signing-key custodians, independent recovery procedures, and the dated results +of custody and publishing checks, including how each result was established. Artifact signing and permission to publish Maven coordinates are separate. The release key is the dedicated **OWASP Java Encoder Release** key in `KEYS`; diff --git a/VERIFYING.md b/VERIFYING.md index 949def9..3a2a4f0 100644 --- a/VERIFYING.md +++ b/VERIFYING.md @@ -13,18 +13,18 @@ confirms that Central serves the same artifacts and signatures. ## Fresh public-only keyring Download the artifact, its original `.asc`, and the trusted `KEYS`. This example -verifies historical 1.4.0 to demonstrate the process; it is not a recommendation -to use that affected release. Substitute the expected project fingerprint and -artifact name for 1.4.1. Commands use GnuPG and `shasum` (or equivalent SHA tools). +verifies the published 1.4.1 release. For historical releases, use the full +fingerprint mapped below and review the historical key's expiry and algorithms. +Commands use GnuPG and `shasum` (or equivalent SHA tools). ```sh verify_home=$(mktemp -d) chmod 700 "$verify_home" -gpg --homedir "$verify_home" --batch --import KEYS -expected_fingerprint=259A55407DD6C00299E6607EFFDE55BE73A2D1ED -artifact=encoder-1.4.0.jar -gpg --homedir "$verify_home" --fingerprint "$expected_fingerprint" -gpg --homedir "$verify_home" --batch --status-fd 1 \ +gpg --homedir "$verify_home" --batch --no-autostart --import KEYS +expected_fingerprint=1C5F632B86809F2F5DB25092BEA0075F94074A9B +artifact=encoder-1.4.1.jar +gpg --homedir "$verify_home" --no-autostart --fingerprint "$expected_fingerprint" +gpg --homedir "$verify_home" --batch --no-autostart --status-fd 1 \ --verify "$artifact.asc" "$artifact" > signature.status || exit 1 awk -v expected="$expected_fingerprint" \ '$2 == "VALIDSIG" && ($3 == expected || $NF == expected) { valid=1 } @@ -45,7 +45,7 @@ A Maven `.sha256` sidecar usually contains **only a hex digest**, not a filename After fetching it over the intended distribution channel, form a check manifest: ```sh -artifact=encoder-1.4.0.jar +artifact=encoder-1.4.1.jar expected_hash=$(tr -d '[:space:]' < "$artifact.sha256") printf '%s\n' "$expected_hash" | grep -Eq '^[[:xdigit:]]{64}$' || exit 1 printf '%s %s\n' "$expected_hash" "$artifact" | shasum -a 256 --check || exit 1 @@ -64,16 +64,17 @@ origin, does not authenticate a publisher. Reviewed 2026-09-26 against the original core JARs and detached signatures at [Maven Central](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/). Every listed original signature mathematically verified in a fresh public-only -keyring; the pre-1.3 keys are now expired. This does not retrospectively authorize -those keys or change any artifact. The table records the primary fingerprint, -not a short key ID, and release-use periods rather than all possible key uses. +keyring; the pre-1.3 certificates archived here are now expired. Signature +verification and the authentication records below are separate evidence. The +table records the primary fingerprint, not a short key ID, and release-use +periods rather than all possible key uses. | Releases | Observed primary fingerprint | Authentication/archival status | | --- | --- | --- | -| 1.1 | `37D880CD406BAD34CA2A8DD61845EF37A3B6533A` | Expired; independent historical full-fingerprint authorization record still missing | -| 1.1.1 | `AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2` | Expired; independent authorization record still missing | -| 1.2 | `C82AF58D3985677F9D575CEC9BC190E3DA071BD4` | Expired; independent authorization record still missing | -| 1.2.1 | `33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE` | Expired; independent authorization record still missing | +| 1.1 | `37D880CD406BAD34CA2A8DD61845EF37A3B6533A` | Expired; archived after Jim Manico's retrospective exact-fingerprint authentication on 2026-09-26 | +| 1.1.1 | `AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2` | Expired; archived after Jim Manico's retrospective exact-fingerprint authentication on 2026-09-26 | +| 1.2 | `C82AF58D3985677F9D575CEC9BC190E3DA071BD4` | Expired; archived after Jim Manico's retrospective exact-fingerprint authentication on 2026-09-26 | +| 1.2.1 | `33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE` | Expired; archived after matching Jeremy Long's public GitHub key record 213069 | | 1.2.2–1.2.3 | `F9514E84AE3708288374BBBE097586CFEA37F9A6` | Expired 2021-10-13; archived in KEYS | | 1.3.0, 1.3.1, 1.4.0 | `259A55407DD6C00299E6607EFFDE55BE73A2D1ED` | Historical personal key; archived in KEYS | | 1.4.1 onward until rotation | `1C5F632B86809F2F5DB25092BEA0075F94074A9B` | Current dedicated project key | @@ -85,17 +86,23 @@ The 1.3.0–1.4.0 fingerprint was already recorded in this project's [KEYS at the rotation](https://github.com/OWASP/owasp-java-encoder/blob/b51c575/KEYS) and is corroborated by the [maintainer's Dependency-Check guide](https://dependency-check.github.io/DependencyCheck/dependency-check-cli/index.html). Retrieved keys were checked against those full records before adding minimal -public exports to KEYS. The first four keys were retrieved only to analyze the -signatures; they are **not** added to trusted archival KEYS without the missing -historical/project authorization records. This is the remaining evidence gap in -#110. Do not resolve it by treating keyserver availability or a matching UID as -project authorization. +public exports to KEYS. For 1.2.1, the primary public-key packet in +[Jeremy's GitHub account key listing](https://api.github.com/users/jeremylong/gpg_keys) +(record 213069, added 2017-08-20) yields the exact full fingerprint above. +For 1.1, 1.1.1 and 1.2, Jim authenticated the exact fingerprints on 2026-09-26, +citing his involvement from the project's beginning and recruitment of Jeff +Ichnowski. This is retrospective maintainer authentication, not a recovered +contemporaneous fingerprint announcement or a claim that Jim held those private +keys. See the [authentication and verification record](releases/historical-key-authentication.md) +for source limits, certificate dates, signature times and artifact hashes. +Keyserver availability and matching UIDs alone are still insufficient authority. The three oldest signatures use SHA-1 and 1.1 uses a 1024-bit DSA key; these are historical facts, not algorithms to use for new releases. Preserve their original bytes/signatures. Current key custody, independent recovery and Central access -remain [MAINTAINERS.md](MAINTAINERS.md) / #111. Record a new authorized project's -full fingerprint before first use and retain the old public verification record. +are recorded in [MAINTAINERS.md](MAINTAINERS.md) / #111. Record each newly authorized +project key's full fingerprint before first use and retain the old public +verification record. OpenPGP detached artifact signing is separate from Java `jarsigner`: it signs the whole downloaded file without adding JAR entries. This project does not claim diff --git a/releases/historical-key-authentication.md b/releases/historical-key-authentication.md new file mode 100644 index 0000000..324991a --- /dev/null +++ b/releases/historical-key-authentication.md @@ -0,0 +1,97 @@ +# Historical signing-key authentication and verification + +Recorded 2026-09-26 (America/Los_Angeles); verification completed +2026-09-27 05:12 UTC. This completes the remaining archival evidence for +[#110](https://github.com/OWASP/owasp-java-encoder/issues/110), following +[PR #185](https://github.com/OWASP/owasp-java-encoder/pull/185). +The complete release-to-fingerprint mapping is in [VERIFYING.md](../VERIFYING.md). + +## Authentication of the four newly archived keys + +Jim Manico explicitly confirmed that he could authenticate the following exact +fingerprints in the maintainer work session on 2026-09-26: + +| Release | Full primary fingerprint | +| --- | --- | +| 1.1 | `37D880CD406BAD34CA2A8DD61845EF37A3B6533A` | +| 1.1.1 | `AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2` | +| 1.2 | `C82AF58D3985677F9D575CEC9BC190E3DA071BD4` | + +Asked for the basis, he stated: “I have been part of this project from the +beginning, I originally recruited Jeff Ichnowski”. This record relies on Jim's +retrospective maintainer authentication. No contemporaneous fingerprint +announcement or separate direct confirmation from Jeremy was recovered for +these three keys. It does not claim that Jim possessed their private keys. +Original authorship, release preparation and artifact signing are distinct; +all four newly archived certificates contain Jeremy Long UIDs. Matching UIDs +or successful signature verification alone were not used as authorization. + +For **1.2.1**, Jeremy's public +[GitHub account GPG-key listing](https://api.github.com/users/jeremylong/gpg_keys) +contains record **213069**, added `2017-08-20T08:20:01.000-07:00`. Decoding its +`public_key` and calculating the version-4 primary-key fingerprint gives +`33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE`, matching the original Central +signature. The returned 272-byte public-key packet has SHA-256 +`5372283957ae77546761756ec6da71fcfebeaebeee3d16e957c47b63a89cdae7`. +The public packet and selected API metadata are preserved in the +[machine-readable evidence](historical-key-evidence.json), so this comparison +does not depend on the account retaining that key indefinitely. This is an +account-associated historical key record, not a new statement by Jeremy. + +The API's `raw_key` was null; it did not supply a complete certificate. Its +expiry metadata extends into 2019, whereas the retrieved full certificate's +self-signature expires in 2017. The archived certificate is the latter; no +unavailable renewal certificate is claimed. The February 2017 artifact signature +predates both expiry dates. The observed API record was not marked revoked. + +Public certificates were transported from Ubuntu's keyserver using each full +fingerprint, then checked against the authentication above. Minimal public +exports were added to [KEYS](../KEYS). The existing three key blocks, including +the current dedicated project key, are byte-for-byte unchanged. No private key, +owner-trust assignment, signature replacement or key-rotation operation is part +of this archival work. + +## Archived certificate dates and historical limits + +| Release | Primary-key creation (UTC) | Archived certificate expiry (UTC) | Original signature packet time (UTC) | +| --- | --- | --- | --- | +| 1.1 | 2012-11-14 02:04:18 | 2013-11-14 02:04:18 | 2013-02-15 01:49:06 | +| 1.1.1 | 2013-11-16 14:53:13 | 2014-11-16 14:53:13 | 2014-01-28 00:57:29 | +| 1.2 | 2015-03-03 11:12:38 | 2017-03-05 15:50:31 | 2015-04-10 19:59:40 | +| 1.2.1 | 2016-04-23 20:53:53 | 2017-04-23 20:53:53 | 2017-02-19 11:59:54 | + +Signature packet times fall within the archived certificates' validity periods; +they are signer-supplied times, not independent timestamp-service attestations. +GnuPG reports `EXPKEYSIG` for 1.1 through 1.2.3 today. The three oldest artifact +signatures use SHA-1; 1.1 also uses 1024-bit DSA. These keys and algorithms are +retained solely for historical verification and are not authorized for new +releases. Consumers with stricter algorithm policies may reject them; this +record does not recommend weakening those policies or deploying old releases. + +## Consumer verification results + +GnuPG 2.5.20 imported the final `KEYS` into a new isolated home containing seven +primary public keys and **zero secret keys**. Each of the ten original Central +core JAR/signature pairs (1.1, 1.1.1, 1.2, 1.2.1, 1.2.2, 1.2.3, 1.3.0, 1.3.1, +1.4.0 and 1.4.1) returned success and `VALIDSIG` with its expected full primary +fingerprint. No weak-digest override, clock substitution or trust assignment +was used. Expiry warnings remain recorded. The JSON evidence contains source +URLs, JAR/signature SHA-256 hashes, certificate dates and signature status for +all ten pairs. These locally computed hashes identify the inspected bytes; +they are not represented as upstream SHA-256 sidecars for old releases. + +Both shell blocks in `VERIFYING.md` ran successfully against the original +Central 1.4.1 core JAR, detached signature and raw SHA-256 sidecar in a separate +fresh public-only home. The analogous raw SHA-512 check also passed. Supplying +the wrong expected fingerprint to the documented status check failed. Both +original 1.4.1 `SHA256SUMS` and `SHA512SUMS` signatures verified against the +dedicated project key, and each manifest passed all 35 checksum entries. +README links to `KEYS` and `VERIFYING.md` are present. + +This verifies the historical core release mapping and the consumer commands; +it does not claim an exhaustive re-download of every historical adapter, +source JAR or POM. The separate [1.4.1 publication audit](1.4.1-central-publication.md) +covers all of that release's published payloads. Original release bytes, tags +and signatures were preserved. Future authorized fingerprints must still be +recorded before first use, and OpenPGP artifact verification remains distinct +from Java `jarsigner` and runtime trust. diff --git a/releases/historical-key-evidence.json b/releases/historical-key-evidence.json new file mode 100644 index 0000000..8ce3f9b --- /dev/null +++ b/releases/historical-key-evidence.json @@ -0,0 +1,198 @@ +{ + "verified_at_utc": "2026-09-27T05:12:28.248695+00:00", + "tool": "gpg (GnuPG) 2.5.20", + "key_source": "../KEYS", + "public_primary_keys": 7, + "secret_keys": 0, + "original_public_key_blocks_preserved": true, + "github_authentication": { + "source": "https://api.github.com/users/jeremylong/gpg_keys", + "record_id": 213069, + "created_at": "2017-08-20T08:20:01.000-07:00", + "fingerprint": "33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE", + "packet_sha256": "5372283957ae77546761756ec6da71fcfebeaebeee3d16e957c47b63a89cdae7", + "revoked": false, + "expires_at": "2019-04-26T20:02:17.000-07:00", + "public_key_packet_base64": "xsBNBFcb4OEBCADKVrVQkQKlqTg4mB/jAoOxBYm3l5tNf4IY5N5hp7sj3HO5S4VtonWvN960K0W+MWUvBVydLaJDcEH1OJXkj58kGwDyBVQjUnnGBgJbs9TtMKyB89ewa1W2OqnXvonFZ0bThpc6LceFV/HBWGIfzjutEPxJpgTQzyI5Ua2BYaLvHP4y6+QTeQIF1fLqodSJxiejmoWdiLx5zkkSKnfRv5MKSYHlNkfu/Pa2JEm//oWEhljyI/R76JmUWw7KaQIW0sjXVOwKnaQMT+ihQjevpvOE2UQMmyuC1kZGRiyfp+Oh3KOTg6NrT7UaII0F4vXOfmTeuD2WrxDBV71TXAJVROpFABEBAAE=", + "raw_key_available": false + }, + "certificates": [ + { + "fingerprint": "1C5F632B86809F2F5DB25092BEA0075F94074A9B", + "bits": 4096, + "openpgp_algorithm_id": 1, + "created_utc": "2026-09-26T01:32:57+00:00", + "expires_utc": "2028-09-25T01:32:57+00:00" + }, + { + "fingerprint": "37D880CD406BAD34CA2A8DD61845EF37A3B6533A", + "bits": 1024, + "openpgp_algorithm_id": 17, + "created_utc": "2012-11-14T02:04:18+00:00", + "expires_utc": "2013-11-14T02:04:18+00:00" + }, + { + "fingerprint": "AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2", + "bits": 2048, + "openpgp_algorithm_id": 1, + "created_utc": "2013-11-16T14:53:13+00:00", + "expires_utc": "2014-11-16T14:53:13+00:00" + }, + { + "fingerprint": "C82AF58D3985677F9D575CEC9BC190E3DA071BD4", + "bits": 2048, + "openpgp_algorithm_id": 1, + "created_utc": "2015-03-03T11:12:38+00:00", + "expires_utc": "2017-03-05T15:50:31+00:00" + }, + { + "fingerprint": "33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE", + "bits": 2048, + "openpgp_algorithm_id": 1, + "created_utc": "2016-04-23T20:53:53+00:00", + "expires_utc": "2017-04-23T20:53:53+00:00" + }, + { + "fingerprint": "F9514E84AE3708288374BBBE097586CFEA37F9A6", + "bits": 2048, + "openpgp_algorithm_id": 1, + "created_utc": "2017-10-13T01:56:33+00:00", + "expires_utc": "2021-10-13T10:17:38+00:00" + }, + { + "fingerprint": "259A55407DD6C00299E6607EFFDE55BE73A2D1ED", + "bits": 4096, + "openpgp_algorithm_id": 1, + "created_utc": "2021-10-07T09:44:56+00:00", + "expires_utc": null + } + ], + "artifacts": [ + { + "version": "1.1", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.1/", + "fingerprint": "37D880CD406BAD34CA2A8DD61845EF37A3B6533A", + "signature_utc": "2013-02-15T01:49:06+00:00", + "jar_sha256": "cdf109ec3dfdfea91dd6415246547202ab9f8e7341c4142bf53920e3e87a9c56", + "signature_sha256": "98a750d3e44b3e1dbe2c437d0012c954dbee5bfa9a0c3ee3568bded549f88ab8", + "gpg_status": [ + "[GNUPG:] KEYEXPIRED 1384394658", + "[GNUPG:] EXPKEYSIG 1845EF37A3B6533A Jeremy Long ", + "[GNUPG:] VALIDSIG 37D880CD406BAD34CA2A8DD61845EF37A3B6533A 2013-02-15 1360892946 0 4 0 17 2 00 37D880CD406BAD34CA2A8DD61845EF37A3B6533A" + ] + }, + { + "version": "1.1.1", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.1.1/", + "fingerprint": "AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2", + "signature_utc": "2014-01-28T00:57:29+00:00", + "jar_sha256": "45195faeb11e5ab6251da4f0f19f06748ab340f3477d2a5eef73bdf8a867c74d", + "signature_sha256": "4570b97df8a4d3b37291102732828262f41f0be7accfa71aa86b011099ea5958", + "gpg_status": [ + "[GNUPG:] KEYEXPIRED 1416149593", + "[GNUPG:] EXPKEYSIG 5AD6F7C8740E3CF2 Jeremy Long ", + "[GNUPG:] VALIDSIG AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2 2014-01-28 1390870649 0 4 0 1 2 00 AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2" + ] + }, + { + "version": "1.2", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.2/", + "fingerprint": "C82AF58D3985677F9D575CEC9BC190E3DA071BD4", + "signature_utc": "2015-04-10T19:59:40+00:00", + "jar_sha256": "ffba2e892b62a1a1864a3ff3e89bf1b30f4ce7eb16f97d067276cfe1269b4927", + "signature_sha256": "0a279a49d313bb914478785b2c7dd5ce0e287a085cecc1e3a6e36683459fee52", + "gpg_status": [ + "[GNUPG:] KEYEXPIRED 1488729031", + "[GNUPG:] EXPKEYSIG 9BC190E3DA071BD4 Jeremy Long ", + "[GNUPG:] VALIDSIG C82AF58D3985677F9D575CEC9BC190E3DA071BD4 2015-04-10 1428695980 0 4 0 1 2 00 C82AF58D3985677F9D575CEC9BC190E3DA071BD4" + ] + }, + { + "version": "1.2.1", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.2.1/", + "fingerprint": "33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE", + "signature_utc": "2017-02-19T11:59:54+00:00", + "jar_sha256": "dd50d40a58b38c81be51239366f0980efc849ab059b5a999ae6155c0a7d59177", + "signature_sha256": "66f2710bef35893a67386b57ada5963e1ac9f57c97e1844925fd8c29bce93c86", + "gpg_status": [ + "[GNUPG:] KEYEXPIRED 1492980833", + "[GNUPG:] EXPKEYSIG F7EBA8ECD6F22BFE Jeremy Long ", + "[GNUPG:] VALIDSIG 33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE 2017-02-19 1487505594 0 4 0 1 8 00 33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE" + ] + }, + { + "version": "1.2.2", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.2.2/", + "fingerprint": "F9514E84AE3708288374BBBE097586CFEA37F9A6", + "signature_utc": "2018-09-03T11:13:11+00:00", + "jar_sha256": "32313d4f4fa494c86cb236664e74723231b9418028c7cfc6d61cc4d14c4a993f", + "signature_sha256": "73bac536d25c3e72adf0a11b859cbaa8eb0b2da8bcd595379ad36c689cade723", + "gpg_status": [ + "[GNUPG:] KEYEXPIRED 1634120258", + "[GNUPG:] EXPKEYSIG 097586CFEA37F9A6 Jeremy Long ", + "[GNUPG:] VALIDSIG F9514E84AE3708288374BBBE097586CFEA37F9A6 2018-09-03 1535973191 0 4 0 1 8 00 F9514E84AE3708288374BBBE097586CFEA37F9A6" + ] + }, + { + "version": "1.2.3", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.2.3/", + "fingerprint": "F9514E84AE3708288374BBBE097586CFEA37F9A6", + "signature_utc": "2020-11-08T18:48:02+00:00", + "jar_sha256": "b09e2cd5c36a7127e091df9be628278b1166b40bc08b9de8196ccddb0cccd67f", + "signature_sha256": "6475a0faa3f3b1a15f1ab69fc3629675010b0caf7d9b8a122be8d79651eae306", + "gpg_status": [ + "[GNUPG:] KEYEXPIRED 1634120258", + "[GNUPG:] EXPKEYSIG 097586CFEA37F9A6 Jeremy Long ", + "[GNUPG:] VALIDSIG F9514E84AE3708288374BBBE097586CFEA37F9A6 2020-11-08 1604861282 0 4 0 1 8 00 F9514E84AE3708288374BBBE097586CFEA37F9A6" + ] + }, + { + "version": "1.3.0", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.3.0/", + "fingerprint": "259A55407DD6C00299E6607EFFDE55BE73A2D1ED", + "signature_utc": "2024-08-02T11:07:41+00:00", + "jar_sha256": "5871da031423337062b30fe8dee82f6b4927d05de432c5d31fe6831083a93808", + "signature_sha256": "9239cf5449d20f4ab36f77e6b3892b0eb04122b35650bf4b37d488f1a255e312", + "gpg_status": [ + "[GNUPG:] VALIDSIG 259A55407DD6C00299E6607EFFDE55BE73A2D1ED 2024-08-02 1722596861 0 4 0 1 8 00 259A55407DD6C00299E6607EFFDE55BE73A2D1ED", + "[GNUPG:] TRUST_UNDEFINED 0 pgp" + ] + }, + { + "version": "1.3.1", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.3.1/", + "fingerprint": "259A55407DD6C00299E6607EFFDE55BE73A2D1ED", + "signature_utc": "2024-08-20T09:51:43+00:00", + "jar_sha256": "c9c56c8970c7cb11b231913ba5190ce930f8fd4fac2bd918810642dc3848e757", + "signature_sha256": "043f441991db85c38eddd6ee607c9abf089c689d5bc0af4fc483f14844ee1616", + "gpg_status": [ + "[GNUPG:] VALIDSIG 259A55407DD6C00299E6607EFFDE55BE73A2D1ED 2024-08-20 1724147503 0 4 0 1 8 00 259A55407DD6C00299E6607EFFDE55BE73A2D1ED", + "[GNUPG:] TRUST_UNDEFINED 0 pgp" + ] + }, + { + "version": "1.4.0", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.4.0/", + "fingerprint": "259A55407DD6C00299E6607EFFDE55BE73A2D1ED", + "signature_utc": "2025-11-17T12:10:32+00:00", + "jar_sha256": "90f9860925905dd97f313cffae065835eb02acc3e2e9b0051621693efd09025c", + "signature_sha256": "4cda8d53deb04d84f5905ff17e972b70ad2f51b453d14155e606b12c0fe9b12f", + "gpg_status": [ + "[GNUPG:] VALIDSIG 259A55407DD6C00299E6607EFFDE55BE73A2D1ED 2025-11-17 1763381432 0 4 0 1 8 00 259A55407DD6C00299E6607EFFDE55BE73A2D1ED", + "[GNUPG:] TRUST_UNDEFINED 0 pgp" + ] + }, + { + "version": "1.4.1", + "source": "https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/1.4.1/", + "fingerprint": "1C5F632B86809F2F5DB25092BEA0075F94074A9B", + "signature_utc": "2026-09-26T01:43:50+00:00", + "jar_sha256": "ee16cdcc2e566989474cf09b381b44d0510385374727d0ef0c62fd2367729229", + "signature_sha256": "99e6d7d1903c5a7bb8fb41328abf76e688a9bcc338245a0d0076aad93019c069", + "gpg_status": [ + "[GNUPG:] VALIDSIG 1C5F632B86809F2F5DB25092BEA0075F94074A9B 2026-09-26 1790387030 0 4 0 1 10 00 1C5F632B86809F2F5DB25092BEA0075F94074A9B", + "[GNUPG:] TRUST_UNDEFINED 0 pgp" + ] + } + ] +} diff --git a/releases/maintenance-closeout.md b/releases/maintenance-closeout.md new file mode 100644 index 0000000..c551ffd --- /dev/null +++ b/releases/maintenance-closeout.md @@ -0,0 +1,72 @@ +# Maintenance backlog closeout + +Audited 2026-09-26 (America/Los_Angeles), after +[PR #208](https://github.com/OWASP/owasp-java-encoder/pull/208) merged as +`1111f7982e492c60abb4897844a02e7b3a44cef7`. The live GitHub inventory before this +documentation PR contained **two open issues (#110 and #169) and zero open +PRs**. This PR supplies the final historical-key evidence and closure record +for those two issues. Its checks, merge and post-merge inventory are recorded +in the linked [maintenance tracker](https://github.com/OWASP/owasp-java-encoder/issues/169). + +## Batch dispositions + +The original tracker reviewed 30 issues and one PR. The final readback found +every other original batch issue closed, with the following dispositions. +The tracker's dated entries retain exact merge commits, validation results, +review/bypass provenance and scope limits; earlier statements of outstanding +#110/#111 work are superseded by the records below, not erased. + +| Batch | Issues and final disposition | Delivery/evidence | +| --- | --- | --- | +| 00 | #112 completed; #111 completed by the publication/access follow-up | PRs #171, #208; [publication and custody evidence](1.4.1-central-publication.md) | +| 01 | #100, #130 completed | PRs #170, #172; tracker validation and migration records | +| 02 | #102, #109, #97, #119, #108 completed | PRs #173, #177; [batch 02 validation](batch-02-validation.md) | +| 03 | #137, #131, #120, #93 completed | PRs #174, #168, #179, #180; tracker validation and consumer/browser evidence | +| 04 | #123, #96, #104, #122, #95, #103, #124, #125 completed; #110 resolved by this archival follow-up | PRs #184, #185, #187; [batch 04 validation](batch-04-validation.md) and [historical-key authentication](historical-key-authentication.md) | +| 05 | #128, #115, #116, #117, #127 completed; #114 consolidated into #128 and closed as not planned, not separately implemented | PR #189; [batch 05 validation](batch-05-validation.md) | +| 06 | #142 completed as a compatibility decision record; #149 rejected and closed as not planned | PR #190; [compatibility decisions](../docs/compatibility-decisions.md) | + +The subsequent dependency queue is also accounted for: Actions PR #175 and +focused Maven PR #191 merged; #176 and #188 closed as superseded. The sixteen +individual proposals #192–#207 were inspected and closed with their specific +compatibility rationale. These were explicit dispositions, not claims that +every proposed upgrade was applied. See the +[dependency decisions](../.github/DEPENDENCY_DECISIONS.md) and +[PR queue validation](pr-queue-validation.md). Future proposals remain subject +to review, and existing scoped dependency/advisory decisions retain their +reconsideration requirements. + +## Final operational and evidence work + +- **#111:** Central deployment `ce91e36f-756c-489f-bbea-3629b728ad28` published + the retained 1.4.1 bundle. All 34 downloaded Central payload/signature files + matched the original signed release. Jim reported both custodians' independent + vault recovery, both publishers' separate validated-then-dropped rehearsals + and Jeremy's namespace access complete on 2026-09-26. The report is explicitly + attributed to Jim; no private rehearsal records or deployment IDs were + independently inspected. PR #208 merged after all 28 checks passed, using the + existing PR-only maintainer review bypass. All four subsequent main workflows + passed: [Java CI](https://github.com/OWASP/owasp-java-encoder/actions/runs/36295798270), + [packaged consumers](https://github.com/OWASP/owasp-java-encoder/actions/runs/36295798276), + [CodeQL](https://github.com/OWASP/owasp-java-encoder/actions/runs/36295798274), and + [dependency submission](https://github.com/OWASP/owasp-java-encoder/actions/runs/36295798278). +- **#110:** the remaining four public keys are archived with explicit + authentication provenance: Jim's retrospective exact-fingerprint confirmation + for 1.1/1.1.1/1.2, and Jeremy's public GitHub key record for 1.2.1. Ten original + core release signatures and current consumer commands passed isolated + verification. Expiry/algorithm limits and the distinction between signing, + authorship and authentication remain visible in the linked evidence. +- **#169:** all seven batches and the subsequent PR queue now have completion + or explicit disposition records. The final documentation PR and post-merge + inventory complete the maintenance execution tracker. + +## The 1.5 release gate remains active + +Closing the maintenance tracker is not approval to release 1.5. Development +remains **`1.5.0-SNAPSHOT`**. When a 1.5 release is actually proposed, repeat the +complete then-open issue/PR inventory and satisfy every requirement in +[RELEASING.md](../RELEASING.md), including review of new work, final artifact +validation and explicit release approval. Deferrals and an empty queue alone +do not authorize signing, tagging or publication. This closeout changes public +key archives and documentation only; it does not change artifact inputs, +repository protections or immutable 1.4.1 release material.