Update dependency org.owasp.encoder:encoder to v1.5.0 - #3116
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/org.owasp.encoder-encoder-1.x
branch
from
October 3, 2026 12:01
34938fd to
c0c864c
Compare
Contributor
Author
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.4.0→1.5.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
OWASP/owasp-java-encoder (org.owasp.encoder:encoder)
v1.5.0Compare Source
This is a security release for
GHSA-g8p6-7r8f-qrpv.
Signed artifact availability and independent verification are tracked in the
1.5.0 release record.
servlet-engine and build-tool version proposals. The ignores are limited to
routine version updates in the rejected SemVer classes; security updates remain
eligible. Mixed historical/current coordinates require manual version review
because Dependabot classifies them from their lowest occurrence.
encoder-esapiadapter. Version 1.4.1 is its final published release and is no longer supported; noencoder-esapi:1.5.0artifact will be published. Consumers must remove the adapter and migrate Java Encoder-backed calls to the direct context APIs. Historical Maven artifacts remain immutable.forJavaScript*methods encode dollar sign ($) as\x24, backtick as\x60, and opening brace ({) as\x7b#129. Escaping{prevents input after a trusted$from completing${...}. Encoded output now supports literal text in ordinary (untagged) template literals as well as single- and double-quoted strings. This changes the encoded output while preserving its decoded JavaScript string value. Tagged templates (includingString.raw),${...}expression bodies, JSON, and script URLs are unsupported; each method's HTML context restrictions still apply.forJavaScript*methods escape unpaired UTF-16 surrogates as\uXXXX, preserving their JavaScript string values through UTF-8 serialization #135, and escape DEL/C1 controls (U+007F to U+009F) as\xNN#163. Valid surrogate pairs and other non-ASCII text remain unescaped except U+2028/U+2029. These are output-fidelity changes; NEL was already ordinary JavaScript string data.</scriptend tag or the<!--and-->script tokens, including the HTML end-tag delimiters, so any nonempty encoded substring cannot complete a delimiter supplied partly by adjacent trusted literal text.forCDATArepresents every]and>with close/reopen sequences, preserving parsed text while breaking every nonempty encoded substring of]]>; its String facade grows with actual output instead of eagerly reserving the 13× maximum.forXmlCommentreplaces every hyphen with~. These are substantial compatibility-visible output changes; see the migration record.EncodedWriternow enforces Writer lifecycle semantics: write, append and flush operations fail after close; repeated close is harmless; the first close finalizes pending input and still attempts the delegate close, preserving simultaneous failures with suppressed exceptions. Array-slice writes now use overflow-safe bounds validation, includingInteger.MAX_VALUE-shaped ranges.Encode.forJsonString/Writer methods, thejsonencoder context, andforJsontags and EL functions in both JSP and Jakarta tag libraries #145. The caller supplies double quotes. Output uses RFC 8259 string escapes and also escapes HTML script delimiters. Javanullbecomes the textnull(the JSON string"null"when quoted); unpaired surrogates use Unicode escapes and may not interoperate with every JSON consumer. Prefer a serializer for complete JSON documents.forXml11,forXml11ContentandforXml11Attributetags and EL functions to the advanced JSP and Jakarta taglibs, andforXml11to the basic taglibs #131.Encoders.URIand bothForUriTagclasses are now deprecated likeEncode.forUri, whose Javadoc now says what to use instead; theforUriTLD descriptions warn about double encoding, the adapter builds show deprecation call sites, and the README has a forUri migration section #130.[1.5,2), because the tags callEncode.forJson) and the JSP API ranges they support, instead of unversioned imports that could wire to an older core and fail when a tag ran. Bundle symbolic names are now declared explicitly and unchanged #137.forHtmlUnquotedAttributenow replaces U+0085 (NEL) with a hyphen like the other C1 control characters, instead of emitting&#​133;, which HTML5 parsers decode as U+2026 #136.forXml11,forXml11Content,forXml11Attribute) now encode U+0085 (NEL) as…and U+2028 (line separator) as
, so they are not normalized to a line feed #136.Build, compatibility and maintenance
and Felix R6/R8; add final TLD-surface/Writer contract checks (#162, #167).
required real-browser and executable-WAR checks with the modernized optional
Boot 4.1.1 fixture (#179, #180).
Maven caches, and preserve required CI/security gates (#173, #177).
and retain attribution (#184).
and JDK 17 build policy, Checkstyle and measured unit coverage floors; isolate
signing/publishing tools, verify local bundles and measure reproducibility
(#185, #187). This does not change the Java 8 library runtime baseline.
guidance (#164, #171, #185). Historical signing-key
authorization records (#110) now distinguish retrospective maintainer
authentication from historical GitHub/project records; see the
key verification record.
Central publication and the reported completion of maintainer access/custody
work (#111) are recorded in the publication follow-up.
The maintenance tracker
and closeout record record the corresponding
PRs, tests and dispositions; they are not approval to publish 1.5.
v1.4.1Compare Source
Signed GitHub release
(tag created 2026-09-25 in America/Los_Angeles).
Available from Maven Central. Upgrade all four Java Encoder artifacts;
versions through 1.4.0 are affected.
Central publication was verified on 2026-09-27 UTC (2026-09-26 in
America/Los_Angeles); all artifacts and signatures match the retained release.
EncodedWritercontext corruption during buffer overflow(GHSA-57jg-769q-93vh).
EncodedWriter(GHSA-q6jj-5396-8mq2).
(GHSA-p9ff-j89j-9xhx).
make adapter API dependencies transitively readable in module descriptors.
See the full release record for affected entry points,
coordinates, verification and publication status. Later 1.5 changes do not alter
these retained artifacts.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.