Skip to content

Bump org.owasp.encoder:encoder from 1.4.0 to 1.5.0 in /cnf - #4014

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/maven/cnf/org.owasp.encoder-encoder-1.5.0
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/maven/cnf/org.owasp.encoder-encoder-1.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps org.owasp.encoder:encoder from 1.4.0 to 1.5.0.

Release notes

Sourced from org.owasp.encoder:encoder's releases.

OWASP Java Encoder 1.5.0

Version 1.5.0 is available from Maven Central. All nine binary/source/Javadoc JARs, four POMs, and their thirteen signatures were downloaded from Central and verified against the retained signed release files. There is no encoder-esapi:1.5.0 release.

Security and correctness

  • Fixes encoded fragments completing outer HTML or XML parser delimiters across trusted-text boundaries in JavaScript HTML/block, CDATA, and XML-comment contexts. Versions through 1.4.1 are affected. See GHSA-g8p6-7r8f-qrpv.
  • Fixes EncodedWriter close/finalization behavior, exception handling, and overflow-safe array-slice validation.
  • Adds JSON encoding APIs and matching JSP/Jakarta tags and EL functions, plus XML 1.1 bindings.

Compatibility and migration

Public Java APIs remain binary and source compatible with 1.4.1 for the three supported libraries. Java 8 remains the minimum runtime; packaged consumers passed on Java 8, 11, 17, 21, and 25.

The security fixes deliberately change some encoded output:

  • JavaScript HTML/block modes emit additional hexadecimal escapes while preserving the string value. Review byte snapshots, cache keys, signatures, and output-size budgets.
  • CDATA preserves parsed text but can expand to 13 output characters per input character and can change parser event boundaries.
  • XML-comment hyphens become ~ under the documented lossy policy.

The optional ESAPI adapter is retired. Version 1.4.1 is its final published release and is unsupported; migrate to direct Java Encoder APIs. Mixing the 1.4.1 adapter with the 1.5 core is not a supported migration.

See the migration notes, ESAPI retirement guide, and changelog.

Maven artifacts

Use group org.owasp.encoder and version 1.5.0:

The optional test WAR and retired ESAPI adapter are not published.

Verification

Exact release source: 3fbc5da5bcdc49a6e2b4f39d3df7410b7c13d07d. The signed v1.5.0 tag identifies this tested commit. PR #229's squash commit 030c137fc14f277afc5fbe303d2ca8a149f8068b has the identical file tree.

Release artifacts were built with Eclipse Temurin 17.0.20.1+1 and the committed Maven 3.9.16 wrapper. All 2,287 local reactor tests passed with zero failures, errors, or skips. All thirteen unsigned payload files matched two fresh source-export builds. Post-merge Java CI, packaged consumers, and CodeQL passed, including the browser and Java 8 gates.

Project signing fingerprint: 1C5F632B86809F2F5DB25092BEA0075F94074A9B.

The assets contain the public KEYS, detached signatures, and signed SHA-256/SHA-512 manifests. Follow the verification instructions, using this full expected fingerprint and the 1.5.0 filenames. Authenticate each checksum manifest's signature before checking its entries.

Central bundle SHA-256: 107b0e4e1f459087d6bbd1e37222c05c7c4630fa55d52bc1e7c99c0077897590.

The source-tag documentation preserves the pre-publication notices from the immutable release commit. This release record confirms the subsequently verified Central publication; publication follow-up documentation belongs in a later commit, not a rebuilt release.

v1.4.1 — Security release

... (truncated)

Changelog

Sourced from org.owasp.encoder:encoder's changelog.

1.5.0 — 2026-09-28 UTC

This is a security release for GHSA-g8p6-7r8f-qrpv. Signed artifact availability and independent verification are tracked in the 1.5.0 release record.

  • build: stop Dependabot from recreating already-reviewed incompatible API, servlet-engine and build-tool version proposals. The ignores are limited to routine version updates in the rejected SemVer classes; security updates remain eligible. Mixed historical/current coordinates require manual version review because Dependabot classifies them from their lowest occurrence.
  • removed: retire the optional encoder-esapi adapter. Version 1.4.1 is its final published release and is no longer supported; no encoder-esapi:1.5.0 artifact will be published. Consumers must remove the adapter and migrate Java Encoder-backed calls to the direct context APIs. Historical Maven artifacts remain immutable.
  • build: remove advisory-affected dependencies from active Maven plugin realms, including the separately invoked compatibility-fixture downloader; invoke the same japicmp engine without its obsolete reporting wrapper; and submit only actually invoked build plugins to GitHub's dependency graph. Shared inherited tooling is recorded once, and no Dependabot alert is dismissed or suppressed.
  • build/compatibility: update the published JSP provided API to 2.3.3 and the Jakarta test classpath to Servlet 6.1.0 and EL 6.0.1, while retaining independent JSP 2.2.1 and Java 8-compatible Jakarta minimum-consumer fixtures. Japicmp now resolves distinct old/new support classpaths so the 1.4.1 comparison remains complete. Dependabot scans the root Maven reactor once, rather than opening duplicate module proposals, and continues to scan the standalone compatibility-fixture project separately.
  • feat: all four forJavaScript* methods encode dollar sign ($) as \x24, backtick as \x60, and opening brace ({) as \x7b #129. Escaping { prevents input after a trusted $ from completing ${...}. Encoded output now supports literal text in ordinary (untagged) template literals as well as single- and double-quoted strings. This changes the encoded output while preserving its decoded JavaScript string value. Tagged templates (including String.raw), ${...} expression bodies, JSON, and script URLs are unsupported; each method's HTML context restrictions still apply.
  • fix: all four forJavaScript* methods escape unpaired UTF-16 surrogates as \uXXXX, preserving their JavaScript string values through UTF-8 serialization #135, and escape DEL/C1 controls (U+007F to U+009F) as \xNN #163. Valid surrogate pairs and other non-ASCII text remain unescaped except U+2028/U+2029. These are output-fidelity changes; NEL was already ordinary JavaScript string data.
  • fix: the HTML/block JavaScript encoders escape every ASCII character that can contribute to a case-insensitive </script end tag or the <!-- and --> script tokens, including the HTML end-tag delimiters, so any nonempty encoded substring cannot complete a delimiter supplied partly by adjacent trusted literal text. forCDATA represents every ] and > with close/reopen sequences, preserving parsed text while breaking every nonempty encoded substring of ]]>; its String facade grows with actual output instead of eagerly reserving the 13× maximum. forXmlComment replaces every hyphen with ~. These are substantial compatibility-visible output changes; see the migration record.
  • fix: EncodedWriter now enforces Writer lifecycle semantics: write, append and flush operations fail after close; repeated close is harmless; the first close finalizes pending input and still attempts the delegate close, preserving simultaneous failures with suppressed exceptions. Array-slice writes now use overflow-safe bounds validation, including Integer.MAX_VALUE-shaped ranges.
  • build: compare all three 1.5.0 artifacts against the immutable 1.4.1 public-API baseline, and verify that every publishable effective POM inherits repository-root SCM connection, developer connection and URL values without module-name suffixes.
  • feat: add Encode.forJson String/Writer methods, the json encoder context, and forJson tags and EL functions in both JSP and Jakarta tag libraries #145. The caller supplies double quotes. Output uses RFC 8259 string escapes and also escapes HTML script delimiters. Java null becomes the text null (the JSON string "null" when quoted); unpaired surrogates use Unicode escapes and may not interoperate with every JSON consumer. Prefer a serializer for complete JSON documents.
  • feat: add forXml11, forXml11Content and forXml11Attribute tags and EL functions to the advanced JSP and Jakarta taglibs, and forXml11 to the basic taglibs #131.
  • deprecation: Encoders.URI and both ForUriTag classes are now deprecated like Encode.forUri, whose Javadoc now says what to use instead; the forUri TLD descriptions warn about double encoding, the adapter builds show deprecation call sites, and the README has a forUri migration section #130.
  • fix: the JSP and Jakarta bundles now declare the core version they need ([1.5,2), because the tags call Encode.forJson) and the JSP API ranges they support, instead of unversioned imports that could wire to an older core and fail when a tag ran. Bundle symbolic names are now declared explicitly and unchanged #137.
  • fix: forHtmlUnquotedAttribute now replaces U+0085 (NEL) with a hyphen like the other C1 control characters, instead of emitting &[#133](https://github.com/OWASP/owasp-java-encoder/issues/133);, which HTML5 parsers decode as U+2026 #136.
  • fix: the XML 1.1 encoders (forXml11, forXml11Content, forXml11Attribute) now encode U+0085 (NEL) as &#x85; and U+2028 (line separator) as &#x2028;, so they are not normalized to a line feed #136.
  • maintenance: clarify output-context contracts and expand XML 1.1 tests, fix clean reactor compilation, and remove the obsolete benchmark profile.

Build, compatibility and maintenance

  • Preserve original-JAR consumers on Java 8/11/17/21/25, explicit/automatic JPMS and Felix R6/R8; add final TLD-surface/Writer contract checks (#162, #167).
  • Test packaged javax/Jakarta TLDs through isolated Tomcat/Jasper engines; retain required real-browser and executable-WAR checks with the modernized optional Boot 4.1.1 fixture (#179, #180).
  • Pin and guard Actions, add CodeQL/dependency submissions/Dependabot, isolate Maven caches, and preserve required CI/security gates (#173, #177).
  • Include Java 9 descriptors in source attachments; normalize source metadata and retain attribution (#184).
  • Retire the dormant Maven Site/OSS parent, adopt verified Maven 3.9.16 wrapper and JDK 17 build policy, Checkstyle and measured unit coverage floors; isolate signing/publishing tools, verify local bundles and measure reproducibility (#185, #187). This does not change the Java 8 library runtime baseline.
  • Add release verification, historical key evidence, and maintainer custody guidance (#164, #171, #185). Historical signing-key authorization records (#110) now distinguish retrospective maintainer authentication from historical GitHub/project records; see the key verification record. Central publication and the reported completion of maintainer access/custody work (#111) are recorded in the publication follow-up.

... (truncated)

Commits
  • 3fbc5da Prepare OWASP Java Encoder 1.5.0 release
  • df219a5 Suppress rejected Dependabot baseline updates (#228)
  • a006309 Consolidate Dependabot API updates (#217)
  • f25c771 Harden 1.5.0 context boundaries and release checks (#210)
  • 07d8e58 Complete historical key archive and maintenance closeout (#209)
  • 1111f79 Record 1.4.1 Central publication and maintainer readiness (#208)
  • 18582d3 Update bundle plugin and isolate compatibility-sensitive dependency proposals...
  • 011734a Update artifact actions with verified pins and strict digest checks (#175)
  • 21705bd Record compatibility commitments and base64url scope decision (#190)
  • 8c32b2c Consolidate consumer docs, release history and community metadata (#189)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.owasp.encoder:encoder](https://github.com/OWASP/owasp-java-encoder) from 1.4.0 to 1.5.0.
- [Release notes](https://github.com/OWASP/owasp-java-encoder/releases)
- [Changelog](https://github.com/OWASP/owasp-java-encoder/blob/main/CHANGELOG.md)
- [Commits](OWASP/owasp-java-encoder@v1.4.0...v1.5.0)

---
updated-dependencies:
- dependency-name: org.owasp.encoder:encoder
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies java Pull requests that update Java code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants