This is an automated email from the ASF dual-hosted git repository.
garydgregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-codec.git
The following commit(s) were added to refs/heads/master by this push:
new 3e05f669 [CODEC-245] Reject malformed Sha2Crypt salt syntax (#445)
3e05f669 is described below
commit 3e05f66920c3ec1d5a2f22f1795a76fdbbfd4e34
Author: Gary Gregory <[email protected]>
AuthorDate: Sat Sep 26 20:26:43 2026 +0000
[CODEC-245] Reject malformed Sha2Crypt salt syntax (#445)
---
src/changes/changes.xml | 1 +
1 file changed, 1 insertion(+)
diff --git a/src/changes/changes.xml b/src/changes/changes.xml
index 59c3aafa..3eea193f 100644
--- a/src/changes/changes.xml
+++ b/src/changes/changes.xml
@@ -69,6 +69,7 @@ The <action> type attribute can be add,update,fix,remove.
<action type="fix" dev="ggregory" due-to="Gary Gregory">Bound Sha2Crypt
password length to prevent quadratic CPU DoS.</action>
<action type="fix" dev="ggregory" due-to="geonseok, Gary Gregory">Make
the @param names in BaseNCodec match the parameters they document
(#444).</action>
<action type="fix" dev="ggregory" due-to="Ganesh Gautam, Gary Gregory"
issue="CODEC-345">Restore URLCodec.encodeUrl(BitSet, byte[]) support for custom
safe sets containing percent and plus, and document the decoding
limitations.</action>
+ <action type="fix" dev="ggregory" due-to="Efe, Gary Gregory"
issue="CODEC-245">Reject malformed Sha2Crypt salt syntax (#445).</action>
<!-- ADD -->
<action type="add" dev="ggregory" due-to="Gary Gregory">Add and use
PhoneticEngine.Builder and deprecate old constructors.</action>
<action type="add" dev="ggregory" due-to="Gary Gregory">Add
BeiderMorseEncoder.Builder and deprecate old constructor.</action>