Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 7 additions & 5 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,13 +40,15 @@ Development builds use `1.5.0-SNAPSHOT`; this is not a published release.
(#185, #187). This does not change the Java 8 library runtime baseline.
- Add release verification, historical key evidence, maintainer custody and
release-specific ESAPI guidance (#164, #171, #185). Historical signing-key
authorization gaps (#110) remain open. Central publication and the reported
completion of maintainer access/custody work (#111) are recorded in the
[publication follow-up](releases/1.4.1-central-publication.md).
authorization records (#110) now distinguish retrospective maintainer
authentication from historical GitHub/project records; see the
[key verification record](releases/historical-key-authentication.md).
Central publication and the reported completion of maintainer access/custody
work (#111) are recorded in the [publication follow-up](releases/1.4.1-central-publication.md).

These items are merged through `3bd86250a9c9cd48577c3bf7fb9c46dbe91c1c90`.
The [maintenance tracker](https://github.com/OWASP/owasp-java-encoder/issues/169)
records PRs, tests and dispositions; it is not approval to publish 1.5.
and [closeout record](releases/maintenance-closeout.md) record the corresponding
PRs, tests and dispositions; they are not approval to publish 1.5.

## 1.4.1 — 2026-09-26 UTC

Expand Down
94 changes: 94 additions & 0 deletions KEYS
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,100 @@ These keys are archival, not authorized for new releases. See VERIFYING.md for
observed version mapping, expiry and source authentication. The current project
key above remains unchanged.

Versions: 1.1
Fingerprint: 37D880CD406BAD34CA2A8DD61845EF37A3B6533A
Authentication record: Jim Manico, retrospective exact-fingerprint authentication, 2026-09-26; see releases/historical-key-authentication.md
Historical verification only; expired certificate, not authorized for new releases.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQGiBFCi/CIRBADETL2sotRoEJ9AGJ8t7CilrL/UnY5YH64rjRPUFr1wgH6RQlh/
gCvyh2lrkPYQiKUvpxNK3WnC9IELPsVR6klFiR35G6WX+hCz3cjns1HsmxQ2+KGx
H1DSMKvzEko12skrlRF/2DOReb8qrG4d+rcW3efFDK69axgWiUIynMlOAwCg+bj3
BJ0e3Je1C5VoSftUoBP8PdMD/ArO7Fg4cBh956ttVvLWmyq0JCoOqoOY51IrvIGq
ue7eYcUcoi6Cb4bKO/FbYTFsJ3BF9pfIRh0Fzutq/Z3CBhkwZUoMNNpGvQfO6aEz
AFy/5Ga5wmzWyVzd3rG+IgI9ZG+V0jEkZG7SOvEFh6ovKrcE1S7NHP75OOBd8/y9
YKTlBACpai6AMaYdT8CT7ORTL2yuukx1Ud0GogoAyxhiecfIz7e8jtOtcOyaF9e0
cTQ5jPOJFxM6ayo0+HjTcGIExgBpIPMrRjGiDxABogc/1PXcsKhEjb/IXL/cFJyB
2+m8a90Nfp+BsTfaM8ecJ9BzhGcOHWcxShyhCnc8O+WjH2tMYrQjSmVyZW15IExv
bmcgPGplcmVteS5sb25nQGdtYWlsLmNvbT6IZQQTEQIAJQUCUKL8IgIbAwUJAeEz
gAYLCQgHAwIEFQIIAwMWAgECHgECF4AACgkQGEXvN6O2Uzp1hwCg5NLgju3nWSc5
vQfzbbcTMm2okSIAnjZejzmqZbZdX/MSuc1PIsMpLiVO
=JC0V
-----END PGP PUBLIC KEY BLOCK-----

Versions: 1.1.1
Fingerprint: AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2
Authentication record: Jim Manico, retrospective exact-fingerprint authentication, 2026-09-26; see releases/historical-key-authentication.md
Historical verification only; expired certificate, not authorized for new releases.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQENBFKHhtkBCACbIO7v+Qlc9hojh9czoQlkrfxuArR6qB0bEyX06r+hInDCyG8L
P2RxiNSSpxM0LmE0+uCZvHnh7gKEfBAc6qa66Awulz3uBI3zHSenIHWynd9NhicY
+LaFrRmL83cvcgxzFNCwsbg1CPyE51aEEy5IMvjz6m/ZclTJhFH3sFy/bhQgYHsP
OdY7mSQ4M5L6wKvtAmXsT9OJpzelOprSa1S7rj5UrzHA/wfl9F3R8DQNU2A7eEXv
vOpBQ7NqOoChcVP1QBLS4/ukmUGHBTXi1hcAu7UZC5vbaq4ApMzOM9j0PLSGXvSU
gyib8H2oLM1dURmn/Agez8IdwvGtK0amDHARABEBAAG0I0plcmVteSBMb25nIDxq
ZXJlbXkubG9uZ0BnbWFpbC5jb20+iQE+BBMBAgAoBQJSh4bZAhsDBQkB4TOABgsJ
CAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRBa1vfIdA488rBVB/952SypkONVnvJx
fQ1rFEPDRGRWX4ElUmhomUxmUJaI0eUa+NL3hTwCrTxtb/HWVDh73pdiaaCTzdBP
9Oco3Nqn1ooCsRl4pv/maIJiM8Fo4q43QzrpWfXyKpO4Cj/vMKnlmZjKpJzlZCSo
TJYxfJcPihS+LYgf2qK0u+i8Gy1Zp9nwn6st2/bFerH4i+PoLqsLOlcPcN7zZF0L
1V3kndi3alX0DsuqZ8eqVYRoIgVO6FnfnnPZub0xXZruQ4yLu7uRbIzoxgTMu1mE
2LysciAmByR19Tg1NP0DfbeY0mhZZzMJgmXtgvGFY8004LIRS3A+NT4fezlUiVMN
4OzbVVpV
=HEeP
-----END PGP PUBLIC KEY BLOCK-----

Versions: 1.2
Fingerprint: C82AF58D3985677F9D575CEC9BC190E3DA071BD4
Authentication record: Jim Manico, retrospective exact-fingerprint authentication, 2026-09-26; see releases/historical-key-authentication.md
Historical verification only; expired certificate, not authorized for new releases.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQENBFT1lyYBCADSHA1nMrkID9RWgJfiimLforeFYEEq3pliZpNrvMJVAdlruJP+
DWyOy3EpxYa8eszbG92Btl4TlG2vtkH5zsv3vpwBKDShLds3+hTNAX9mXTSovJYP
iquLISkCrZ3BwY9ezKGTG2AsmJy8Uogy1TSnk9qJqO/fUHU00MO2YpkVAu7j6Cjo
Jgygy5T6Z35uQJIfmppcuTcfAbG82umcy+FjqftPGhO/hyh0KUQR3H6ovbuogPB4
l8STH9ZA31JOYe46+HP6KJHWaIK/YM7DMKDBuSI6kzFQnUatO6yv88d2zNys3J2L
shGeZEh652FLUBJ5rmpMAIMJPzAREggnJNuFABEBAAG0I0plcmVteSBMb25nIDxq
ZXJlbXkubG9uZ0Bvd2FzcC5vcmc+iQE+BBMBAgAoAhsDBgsJCAcDAgYVCAIJCgsE
FgIDAQIeAQIXgAUCVtsARwUJA8acoQAKCRCbwZDj2gcb1JQpCAC1lpzyq3X7lLWx
wuhqeKgK9IzLxlnV7iek/XbWXaVwGwEhoOYpq7xzuGWNkpjvNCWJ9fXyIYDU4+tF
S9ssINrl0Acw3aDkt6/AkM7g4aC0OegHR6tNZV6YZYUnhhQwJQO+SwZ3+JfkPpB8
oznZ0lo7QUVPcUjAV6/JABAwyZSnvNnlYGzIIGCFWrLnRREBd83UiqErZDZAm1W0
qljqFJJaZUWm5jJ/GxKFBrFYW57s4W3Ih6PrS1TOpfX0LcsZJRMyirQ32VwOWmNF
l/3QUkepAbTyLesxHfLjqAbwekgC8AMs1dXE6RTHRbaIrHCn3ezGxKFZmn045+0R
4cW16KiG
=adbD
-----END PGP PUBLIC KEY BLOCK-----

Versions: 1.2.1
Fingerprint: 33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE
Authentication record: Jeremy Long's public GitHub GPG-key record 213069; see releases/historical-key-authentication.md
Historical verification only; expired certificate, not authorized for new releases.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQENBFcb4OEBCADKVrVQkQKlqTg4mB/jAoOxBYm3l5tNf4IY5N5hp7sj3HO5S4Vt
onWvN960K0W+MWUvBVydLaJDcEH1OJXkj58kGwDyBVQjUnnGBgJbs9TtMKyB89ew
a1W2OqnXvonFZ0bThpc6LceFV/HBWGIfzjutEPxJpgTQzyI5Ua2BYaLvHP4y6+QT
eQIF1fLqodSJxiejmoWdiLx5zkkSKnfRv5MKSYHlNkfu/Pa2JEm//oWEhljyI/R7
6JmUWw7KaQIW0sjXVOwKnaQMT+ihQjevpvOE2UQMmyuC1kZGRiyfp+Oh3KOTg6Nr
T7UaII0F4vXOfmTeuD2WrxDBV71TXAJVROpFABEBAAG0I0plcmVteSBMb25nIDxq
ZXJlbXkubG9uZ0BnbWFpbC5jb20+iQE/BBMBCAApBQJXG+DhAhsDBQkB4TOABwsJ
CAcDAgEGFQgCCQoLBBYCAwECHgECF4AACgkQ9+uo7NbyK/65gwgAgXE+wo69vhS5
DHs4aqcaLHcLcH+oiLitgMiRd/TQvX+iB9sVln2d2+yulo5auMrccSLhF+HAT4u6
0IOFtKqfhZJA7ogtvwS4UOC6Zz3ZGk0VEalsaQWC6SAck8cCJlXJ6Z7Z61Tasfw8
5m+N0LDoiqldHFGoTQaXGpnvMoLtMLO0g75xkTxHIi59YSRnEMJiKgMYv4+lznai
hMiAxqyGBHDyux2L7ypI6LYSKkzAVtfZXHJxwwzrXtpcqpqCUHqrFG02n+yvS9Vm
sm9AKdrlg0JSM/JmcUlD7UCCYVL21X1n2JHsvjOKszf1YjJ/msvrCa+GxtYhmP+5
R66aTuxIsg==
=u974
-----END PGP PUBLIC KEY BLOCK-----

Versions: 1.2.2-1.2.3
Fingerprint: F9514E84AE3708288374BBBE097586CFEA37F9A6
Authentication record: Jeremy Long's OWASP Dependency-Check v6.0.0 CLI verification guide (2020)
Expand Down
9 changes: 7 additions & 2 deletions RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,15 +9,20 @@ or verification for every item. Completing a maintenance batch does not satisfy
this gate on its own. Keep 1.5 development at `1.5.0-SNAPSHOT`; snapshot version
changes and reviewed maintenance merges are not release approval.

The [2026-09-26 maintenance closeout](releases/maintenance-closeout.md) records
the final backlog inventory and dispositions for #110 and #169. A closed tracker
does not waive this gate: repeat the complete open-issue/PR inventory when a 1.5
release is actually proposed and obtain release approval then.

The signed 1.4.1 release has been [published to Central and verified](releases/1.4.1-central-publication.md).
That publication is separate from the 1.5 release gate. Do not rebuild or replace
1.4.1 artifacts, republish its coordinates, or move its tag.

## Publishing access and project identity

See [MAINTAINERS.md](MAINTAINERS.md) for named maintainers, security contacts,
signing-key custodians, independent recovery procedures, and the dated status
of outstanding custody and publishing checks.
signing-key custodians, independent recovery procedures, and the dated results
of custody and publishing checks, including how each result was established.

Artifact signing and permission to publish Maven coordinates are separate.
The release key is the dedicated **OWASP Java Encoder Release** key in `KEYS`;
Expand Down
53 changes: 30 additions & 23 deletions VERIFYING.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,18 +13,18 @@ confirms that Central serves the same artifacts and signatures.
## Fresh public-only keyring

Download the artifact, its original `.asc`, and the trusted `KEYS`. This example
verifies historical 1.4.0 to demonstrate the process; it is not a recommendation
to use that affected release. Substitute the expected project fingerprint and
artifact name for 1.4.1. Commands use GnuPG and `shasum` (or equivalent SHA tools).
verifies the published 1.4.1 release. For historical releases, use the full
fingerprint mapped below and review the historical key's expiry and algorithms.
Commands use GnuPG and `shasum` (or equivalent SHA tools).

```sh
verify_home=$(mktemp -d)
chmod 700 "$verify_home"
gpg --homedir "$verify_home" --batch --import KEYS
expected_fingerprint=259A55407DD6C00299E6607EFFDE55BE73A2D1ED
artifact=encoder-1.4.0.jar
gpg --homedir "$verify_home" --fingerprint "$expected_fingerprint"
gpg --homedir "$verify_home" --batch --status-fd 1 \
gpg --homedir "$verify_home" --batch --no-autostart --import KEYS
expected_fingerprint=1C5F632B86809F2F5DB25092BEA0075F94074A9B
artifact=encoder-1.4.1.jar
gpg --homedir "$verify_home" --no-autostart --fingerprint "$expected_fingerprint"
gpg --homedir "$verify_home" --batch --no-autostart --status-fd 1 \
--verify "$artifact.asc" "$artifact" > signature.status || exit 1
awk -v expected="$expected_fingerprint" \
'$2 == "VALIDSIG" && ($3 == expected || $NF == expected) { valid=1 }
Expand All @@ -45,7 +45,7 @@ A Maven `.sha256` sidecar usually contains **only a hex digest**, not a filename
After fetching it over the intended distribution channel, form a check manifest:

```sh
artifact=encoder-1.4.0.jar
artifact=encoder-1.4.1.jar
expected_hash=$(tr -d '[:space:]' < "$artifact.sha256")
printf '%s\n' "$expected_hash" | grep -Eq '^[[:xdigit:]]{64}$' || exit 1
printf '%s %s\n' "$expected_hash" "$artifact" | shasum -a 256 --check || exit 1
Expand All @@ -64,16 +64,17 @@ origin, does not authenticate a publisher.
Reviewed 2026-09-26 against the original core JARs and detached signatures at
[Maven Central](https://repo.maven.apache.org/maven2/org/owasp/encoder/encoder/).
Every listed original signature mathematically verified in a fresh public-only
keyring; the pre-1.3 keys are now expired. This does not retrospectively authorize
those keys or change any artifact. The table records the primary fingerprint,
not a short key ID, and release-use periods rather than all possible key uses.
keyring; the pre-1.3 certificates archived here are now expired. Signature
verification and the authentication records below are separate evidence. The
table records the primary fingerprint, not a short key ID, and release-use
periods rather than all possible key uses.

| Releases | Observed primary fingerprint | Authentication/archival status |
| --- | --- | --- |
| 1.1 | `37D880CD406BAD34CA2A8DD61845EF37A3B6533A` | Expired; independent historical full-fingerprint authorization record still missing |
| 1.1.1 | `AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2` | Expired; independent authorization record still missing |
| 1.2 | `C82AF58D3985677F9D575CEC9BC190E3DA071BD4` | Expired; independent authorization record still missing |
| 1.2.1 | `33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE` | Expired; independent authorization record still missing |
| 1.1 | `37D880CD406BAD34CA2A8DD61845EF37A3B6533A` | Expired; archived after Jim Manico's retrospective exact-fingerprint authentication on 2026-09-26 |
| 1.1.1 | `AD0C981AEE36D3880512E28F5AD6F7C8740E3CF2` | Expired; archived after Jim Manico's retrospective exact-fingerprint authentication on 2026-09-26 |
| 1.2 | `C82AF58D3985677F9D575CEC9BC190E3DA071BD4` | Expired; archived after Jim Manico's retrospective exact-fingerprint authentication on 2026-09-26 |
| 1.2.1 | `33F28D32BAB335D03EC5DAD6F7EBA8ECD6F22BFE` | Expired; archived after matching Jeremy Long's public GitHub key record 213069 |
| 1.2.2–1.2.3 | `F9514E84AE3708288374BBBE097586CFEA37F9A6` | Expired 2021-10-13; archived in KEYS |
| 1.3.0, 1.3.1, 1.4.0 | `259A55407DD6C00299E6607EFFDE55BE73A2D1ED` | Historical personal key; archived in KEYS |
| 1.4.1 onward until rotation | `1C5F632B86809F2F5DB25092BEA0075F94074A9B` | Current dedicated project key |
Expand All @@ -85,17 +86,23 @@ The 1.3.0–1.4.0 fingerprint was already recorded in this project's
[KEYS at the rotation](https://github.com/OWASP/owasp-java-encoder/blob/b51c575/KEYS)
and is corroborated by the [maintainer's Dependency-Check guide](https://dependency-check.github.io/DependencyCheck/dependency-check-cli/index.html).
Retrieved keys were checked against those full records before adding minimal
public exports to KEYS. The first four keys were retrieved only to analyze the
signatures; they are **not** added to trusted archival KEYS without the missing
historical/project authorization records. This is the remaining evidence gap in
#110. Do not resolve it by treating keyserver availability or a matching UID as
project authorization.
public exports to KEYS. For 1.2.1, the primary public-key packet in
[Jeremy's GitHub account key listing](https://api.github.com/users/jeremylong/gpg_keys)
(record 213069, added 2017-08-20) yields the exact full fingerprint above.
For 1.1, 1.1.1 and 1.2, Jim authenticated the exact fingerprints on 2026-09-26,
citing his involvement from the project's beginning and recruitment of Jeff
Ichnowski. This is retrospective maintainer authentication, not a recovered
contemporaneous fingerprint announcement or a claim that Jim held those private
keys. See the [authentication and verification record](releases/historical-key-authentication.md)
for source limits, certificate dates, signature times and artifact hashes.
Keyserver availability and matching UIDs alone are still insufficient authority.

The three oldest signatures use SHA-1 and 1.1 uses a 1024-bit DSA key; these are
historical facts, not algorithms to use for new releases. Preserve their original
bytes/signatures. Current key custody, independent recovery and Central access
remain [MAINTAINERS.md](MAINTAINERS.md) / #111. Record a new authorized project's
full fingerprint before first use and retain the old public verification record.
are recorded in [MAINTAINERS.md](MAINTAINERS.md) / #111. Record each newly authorized
project key's full fingerprint before first use and retain the old public
verification record.

OpenPGP detached artifact signing is separate from Java `jarsigner`: it signs the
whole downloaded file without adding JAR entries. This project does not claim
Expand Down
Loading
Loading