Skip to content

Update dependency org.owasp.encoder:encoder to v1.5.0 - #3116

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/org.owasp.encoder-encoder-1.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/org.owasp.encoder-encoder-1.x

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.owasp.encoder:encoder (source) 1.4.0 → 1.5.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

OWASP/owasp-java-encoder (org.owasp.encoder:encoder)

v1.5.0

Compare Source

This is a security release for
GHSA-g8p6-7r8f-qrpv.
Signed artifact availability and independent verification are tracked in the
1.5.0 release record.

  • build: stop Dependabot from recreating already-reviewed incompatible API,
    servlet-engine and build-tool version proposals. The ignores are limited to
    routine version updates in the rejected SemVer classes; security updates remain
    eligible. Mixed historical/current coordinates require manual version review
    because Dependabot classifies them from their lowest occurrence.
  • removed: retire the optional encoder-esapi adapter. Version 1.4.1 is its final published release and is no longer supported; no encoder-esapi:1.5.0 artifact will be published. Consumers must remove the adapter and migrate Java Encoder-backed calls to the direct context APIs. Historical Maven artifacts remain immutable.
  • build: remove advisory-affected dependencies from active Maven plugin realms, including the separately invoked compatibility-fixture downloader; invoke the same japicmp engine without its obsolete reporting wrapper; and submit only actually invoked build plugins to GitHub's dependency graph. Shared inherited tooling is recorded once, and no Dependabot alert is dismissed or suppressed.
  • build/compatibility: update the published JSP provided API to 2.3.3 and the Jakarta test classpath to Servlet 6.1.0 and EL 6.0.1, while retaining independent JSP 2.2.1 and Java 8-compatible Jakarta minimum-consumer fixtures. Japicmp now resolves distinct old/new support classpaths so the 1.4.1 comparison remains complete. Dependabot scans the root Maven reactor once, rather than opening duplicate module proposals, and continues to scan the standalone compatibility-fixture project separately.
  • feat: all four forJavaScript* methods encode dollar sign ($) as \x24, backtick as \x60, and opening brace ({) as \x7b #​129. Escaping { prevents input after a trusted $ from completing ${...}. Encoded output now supports literal text in ordinary (untagged) template literals as well as single- and double-quoted strings. This changes the encoded output while preserving its decoded JavaScript string value. Tagged templates (including String.raw), ${...} expression bodies, JSON, and script URLs are unsupported; each method's HTML context restrictions still apply.
  • fix: all four forJavaScript* methods escape unpaired UTF-16 surrogates as \uXXXX, preserving their JavaScript string values through UTF-8 serialization #​135, and escape DEL/C1 controls (U+007F to U+009F) as \xNN #​163. Valid surrogate pairs and other non-ASCII text remain unescaped except U+2028/U+2029. These are output-fidelity changes; NEL was already ordinary JavaScript string data.
  • fix: the HTML/block JavaScript encoders escape every ASCII character that can contribute to a case-insensitive </script end tag or the <!-- and --> script tokens, including the HTML end-tag delimiters, so any nonempty encoded substring cannot complete a delimiter supplied partly by adjacent trusted literal text. forCDATA represents every ] and > with close/reopen sequences, preserving parsed text while breaking every nonempty encoded substring of ]]>; its String facade grows with actual output instead of eagerly reserving the 13× maximum. forXmlComment replaces every hyphen with ~. These are substantial compatibility-visible output changes; see the migration record.
  • fix: EncodedWriter now enforces Writer lifecycle semantics: write, append and flush operations fail after close; repeated close is harmless; the first close finalizes pending input and still attempts the delegate close, preserving simultaneous failures with suppressed exceptions. Array-slice writes now use overflow-safe bounds validation, including Integer.MAX_VALUE-shaped ranges.
  • build: compare all three 1.5.0 artifacts against the immutable 1.4.1 public-API baseline, and verify that every publishable effective POM inherits repository-root SCM connection, developer connection and URL values without module-name suffixes.
  • feat: add Encode.forJson String/Writer methods, the json encoder context, and forJson tags and EL functions in both JSP and Jakarta tag libraries #​145. The caller supplies double quotes. Output uses RFC 8259 string escapes and also escapes HTML script delimiters. Java null becomes the text null (the JSON string "null" when quoted); unpaired surrogates use Unicode escapes and may not interoperate with every JSON consumer. Prefer a serializer for complete JSON documents.
  • feat: add forXml11, forXml11Content and forXml11Attribute tags and EL functions to the advanced JSP and Jakarta taglibs, and forXml11 to the basic taglibs #​131.
  • deprecation: Encoders.URI and both ForUriTag classes are now deprecated like Encode.forUri, whose Javadoc now says what to use instead; the forUri TLD descriptions warn about double encoding, the adapter builds show deprecation call sites, and the README has a forUri migration section #​130.
  • fix: the JSP and Jakarta bundles now declare the core version they need ([1.5,2), because the tags call Encode.forJson) and the JSP API ranges they support, instead of unversioned imports that could wire to an older core and fail when a tag ran. Bundle symbolic names are now declared explicitly and unchanged #​137.
  • fix: forHtmlUnquotedAttribute now replaces U+0085 (NEL) with a hyphen like the other C1 control characters, instead of emitting &#&#8203;133;, which HTML5 parsers decode as U+2026 #​136.
  • fix: the XML 1.1 encoders (forXml11, forXml11Content, forXml11Attribute) now encode U+0085 (NEL) as &#x85; and U+2028 (line separator) as &#x2028;, so they are not normalized to a line feed #​136.
  • maintenance: clarify output-context contracts and expand XML 1.1 tests, fix clean reactor compilation, and remove the obsolete benchmark profile.
Build, compatibility and maintenance
  • Preserve original-JAR consumers on Java 8/11/17/21/25, explicit/automatic JPMS
    and Felix R6/R8; add final TLD-surface/Writer contract checks (#​162, #​167).
  • Test packaged javax/Jakarta TLDs through isolated Tomcat/Jasper engines; retain
    required real-browser and executable-WAR checks with the modernized optional
    Boot 4.1.1 fixture (#​179, #​180).
  • Pin and guard Actions, add CodeQL/dependency submissions/Dependabot, isolate
    Maven caches, and preserve required CI/security gates (#​173, #​177).
  • Include Java 9 descriptors in source attachments; normalize source metadata
    and retain attribution (#​184).
  • Retire the dormant Maven Site/OSS parent, adopt verified Maven 3.9.16 wrapper
    and JDK 17 build policy, Checkstyle and measured unit coverage floors; isolate
    signing/publishing tools, verify local bundles and measure reproducibility
    (#​185, #​187). This does not change the Java 8 library runtime baseline.
  • Add release verification, historical key evidence, and maintainer custody
    guidance (#​164, #​171, #​185). Historical signing-key
    authorization records (#​110) now distinguish retrospective maintainer
    authentication from historical GitHub/project records; see the
    key verification record.
    Central publication and the reported completion of maintainer access/custody
    work (#​111) are recorded in the publication follow-up.

The maintenance tracker
and closeout record record the corresponding
PRs, tests and dispositions; they are not approval to publish 1.5.

v1.4.1

Compare Source

Signed GitHub release
(tag created 2026-09-25 in America/Los_Angeles).
Available from Maven Central. Upgrade all four Java Encoder artifacts;
versions through 1.4.0 are affected.

Central publication was verified on 2026-09-27 UTC (2026-09-26 in
America/Los_Angeles); all artifacts and signatures match the retained release.

  • Fix EncodedWriter context corruption during buffer overflow
    (GHSA-57jg-769q-93vh).
  • Fix insufficient-lookahead infinite loops in EncodedWriter
    (GHSA-q6jj-5396-8mq2).
  • Fix CSS String API maximum-output sizing for long U+2028/U+2029 runs
    (GHSA-p9ff-j89j-9xhx).
  • Preserve Java 8 runtime, public method signatures, Maven and JPMS identities;
    make adapter API dependencies transitively readable in module descriptors.
  • Pin the ESAPI adapter's default to 2.7.0.0 rather than a Maven version range.

See the full release record for affected entry points,
coordinates, verification and publication status. Later 1.5 changes do not alter
these retained artifacts.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/org.owasp.encoder-encoder-1.x branch from 34938fd to c0c864c Compare October 3, 2026 12:01
@renovate renovate Bot changed the title Update dependency org.owasp.encoder:encoder to v1.4.1 Update dependency org.owasp.encoder:encoder to v1.5.0 Oct 3, 2026
@renovate

renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: gradle/libs.versions.toml
Command failed: ./gradlew -Dorg.gradle.jvmargs=-Xms512m -Xmx512m --console=plain --dependency-verification lenient -q properties

FAILURE: Build failed with an exception.

* Where:
Settings file '/tmp/renovate/repos/github/diffplug/spotless/settings.gradle.kts' line: 9

* What went wrong:
Error resolving plugin [id: 'com.diffplug.spotless', version: '8.10.3', apply: false]
> A problem occurred configuring project ':build-logic'.
   > Could not resolve all artifacts for configuration 'classpath'.
      > Could not resolve org.jetbrains.kotlin:kotlin-stdlib:2.4.10.
        Required by:
            buildscript of project ':build-logic'
            buildscript of project ':build-logic' > org.gradle.kotlin.kotlin-dsl:org.gradle.kotlin.kotlin-dsl.gradle.plugin:6.7.6 > org.gradle.kotlin:gradle-kotlin-dsl-plugins:6.7.6
         > Could not resolve org.jetbrains.kotlin:kotlin-stdlib:2.4.10.
            > Could not get resource 'https://plugins.gradle.org/m2/org/jetbrains/kotlin/kotlin-stdlib/2.4.10/kotlin-stdlib-2.4.10.pom'.
               > Could not GET 'https://repo.maven.apache.org/maven2/org/jetbrains/kotlin/kotlin-stdlib/2.4.10/kotlin-stdlib-2.4.10.pom'.
                  > Received status code 403 from server: Forbidden
      > Could not resolve org.jetbrains.kotlin:kotlin-gradle-plugin:2.4.10.
        Required by:
            buildscript of project ':build-logic' > org.gradle.kotlin.kotlin-dsl:org.gradle.kotlin.kotlin-dsl.gradle.plugin:6.7.6 > org.gradle.kotlin:gradle-kotlin-dsl-plugins:6.7.6
         > Could not resolve org.jetbrains.kotlin:kotlin-gradle-plugin:2.4.10.
            > Could not parse POM https://plugins.gradle.org/m2/org/jetbrains/kotlin/kotlin-gradle-plugin/2.4.10/kotlin-gradle-plugin-2.4.10.pom
               > Could not resolve org.jetbrains.kotlin:kotlin-gradle-plugins-bom:2.4.10.
                  > Could not resolve org.jetbrains.kotlin:kotlin-gradle-plugins-bom:2.4.10.
                     > Could not get resource 'https://plugins.gradle.org/m2/org/jetbrains/kotlin/kotlin-gradle-plugins-bom/2.4.10/kotlin-gradle-plugins-bom-2.4.10.pom'.
                        > Could not GET 'https://repo.maven.apache.org/maven2/org/jetbrains/kotlin/kotlin-gradle-plugins-bom/2.4.10/kotlin-gradle-plugins-bom-2.4.10.pom'.
                           > Received status code 403 from server: Forbidden
      > Could not resolve org.jetbrains.kotlin:kotlin-gradle-plugin-api:2.4.10.
        Required by:
            buildscript of project ':build-logic' > org.gradle.kotlin.kotlin-dsl:org.gradle.kotlin.kotlin-dsl.gradle.plugin:6.7.6 > org.gradle.kotlin:gradle-kotlin-dsl-plugins:6.7.6
         > Could not resolve org.jetbrains.kotlin:kotlin-gradle-plugin-api:2.4.10.
            > Could not get resource 'https://plugins.gradle.org/m2/org/jetbrains/kotlin/kotlin-gradle-plugin-api/2.4.10/kotlin-gradle-plugin-api-2.4.10.pom'.
               > Could not GET 'https://repo.maven.apache.org/maven2/org/jetbrains/kotlin/kotlin-gradle-plugin-api/2.4.10/kotlin-gradle-plugin-api-2.4.10.pom'.
                  > Received status code 403 from server: Forbidden
> There are 2 more failures with identical causes.

* Try:
> Run with --stacktrace option to get the stack trace.
> Run with --info or --debug option to get more log output.
> Run with --scan to get full insights from a Build Scan (powered by Develocity).
> Get more help at https://help.gradle.org.

BUILD FAILED in 20s

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants