This is an automated email from the ASF dual-hosted git repository.
garydgregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-codec.git
The following commit(s) were added to refs/heads/master by this push:
new d7bff678 Prepare for the release candidate
d7bff678 is described below
commit d7bff678de1efdf767f713c5a178ba9dd9e1562d
Author: Gary Gregory <[email protected]>
AuthorDate: Sun Oct 4 12:59:30 2026 +0000
Prepare for the release candidate
---
CONTRIBUTING.md | 26 ++++++++--------
README.md | 10 +++---
RELEASE-NOTES.txt | 67 ++++++++++++++++++++++++++++++++++++++++
src/changes/changes.xml | 2 +-
src/site/xdoc/download_codec.xml | 28 ++++++++---------
src/site/xdoc/issue-tracking.xml | 10 +++---
6 files changed, 105 insertions(+), 38 deletions(-)
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 30a2a525..7d619927 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -41,35 +41,35 @@
Contributing to Apache Commons Codec
======================
-Have you found a bug or have an idea for a cool new feature? Contributing code
is a great way to give something back to the open-source community.
-Before you dig right into the code, we need contributors to follow a few
guidelines to have a chance of keeping on top of things.
+Have you found a bug, or do you have an idea for a cool new feature?
Contributing code is a great way to give something back to the open-source
community.
+Before you dig right into the code, please review these guidelines to help us
manage contributions.
Getting Started
---------------
+ Make sure you have a [JIRA account](https://issues.apache.org/jira/).
-+ Make sure you have a [GitHub account](https://github.com/signup/free). This
is not essential, but makes providing patches much easier.
-+ If you're planning to implement a new feature it makes sense to discuss your
changes on the [dev list](https://commons.apache.org/mail-lists.html) first.
This way you can make sure you're not wasting your time on something that isn't
considered to be in Apache Commons Codec's scope.
++ Make sure you have a [GitHub account](https://github.com/signup). This is
not essential, but it makes providing patches much easier.
++ If you're planning to implement a new feature, it makes sense to discuss
your changes on the [dev list](https://commons.apache.org/mail-lists.html)
first. This way you can make sure you're not wasting your time on something
that isn't considered to be in Apache Commons Codec's scope.
+ Submit a [Jira Ticket][jira] for your issue, assuming one does not already
exist.
- + Clearly describe the issue including steps to reproduce when it is a bug.
+ + Clearly describe the issue, including steps to reproduce it if it is a bug.
+ Make sure you fill in the earliest version that you know has the issue.
+ Find the corresponding [repository on
GitHub](https://github.com/apache/?query=commons-),
-[fork](https://help.github.com/articles/fork-a-repo/) and check out your
forked repository. If you don't have a GitHub account, you can still clone the
Commons repository.
+[fork](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/fork-a-repo)
and check out your forked repository. If you don't have a GitHub account, you
can still clone the Commons repository.
Making Changes
--------------
+ Create a _topic branch_ for your isolated work.
- * Usually you should base your branch from the `master` branch.
- * A good topic branch name can be the JIRA bug ID plus a keyword, e.g.
`CODEC-123-InputStream`.
+ * Usually, you should base your branch on the `master` branch.
+ * A good topic branch name can be the JIRA bug ID plus a keyword, e.g.,
`CODEC-123-InputStream`.
* If you have submitted multiple JIRA issues, try to maintain separate
branches and pull requests.
+ Make commits of logical units.
* Make sure your commit messages are meaningful and in the proper format.
Your commit message should contain the key of the JIRA issue.
* For example, `[CODEC-123] Close input stream sooner`
+ Respect the original code style:
+ Only use spaces for indentation; you can check for unnecessary whitespace
with `git diff` before committing.
- + Create minimal diffs - disable _On Save_ actions like _Reformat Source
Code_ or _Organize Imports_. If you feel the source code should be reformatted
create a separate PR for this change first.
-+ Write unit tests that match behavioral changes, where the tests fail if the
changes to the runtime are not applied. This may not always be possible but is
a best practice.
+ + Create minimal diffs: disable _On Save_ actions like _Reformat Source
Code_ or _Organize Imports_. If you feel the source code should be reformatted,
create a separate PR for this change first.
++ Write unit tests that match behavioral changes, where the tests fail if the
changes to the runtime are not applied. This may not always be possible, but it
is a best practice.
Unit tests are typically in the `src/test/java` directory.
+ Run a successful build using the default [Maven](https://maven.apache.org/)
goal with `mvn`; that's `mvn` on the command line by itself.
+ Write a pull request description that is detailed enough to understand what
the pull request does, how, and why.
@@ -95,7 +95,7 @@ Submitting Changes
+ Push your changes to a topic branch in your fork of the repository.
+ Submit a _Pull Request_ to the corresponding repository in the `apache`
organization.
* Verify _Files Changed_ shows only your intended changes and does not
- include additional files like `target/*.class`
+ include additional files like `target/*.class`.
+ Update your JIRA ticket and include a link to the pull request in the ticket.
If you prefer to not use GitHub, then you can instead use
@@ -108,8 +108,8 @@ Additional Resources
+ [Contributing patches](https://commons.apache.org/patches.html)
+ [Apache Commons Codec JIRA project page][jira]
+ [Contributor License Agreement][cla]
-+ [General GitHub documentation](https://help.github.com/)
-+ [GitHub pull request
documentation](https://help.github.com/articles/creating-a-pull-request/)
++ [General GitHub documentation](https://docs.github.com/)
++ [GitHub pull request
documentation](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/creating-a-pull-request)
[cla]:https://www.apache.org/licenses/#clas
[jira]:https://issues.apache.org/jira/browse/CODEC
diff --git a/README.md b/README.md
index d796d483..ad3f405e 100644
--- a/README.md
+++ b/README.md
@@ -45,9 +45,9 @@ Apache Commons Codec
[](https://github.com/apache/commons-codec/actions/workflows/maven.yml)
[](https://search.maven.org/artifact/commons-codec/commons-codec)
-[](https://javadoc.io/doc/commons-codec/commons-codec/1.22.1)
+[](https://javadoc.io/doc/commons-codec/commons-codec/1.23.0)
[](https://github.com/apache/commons-codec/actions/workflows/codeql-analysis.yml)
-[](https://api.securityscorecards.dev/projects/github.com/apache/commons-codec)
+[](https://scorecard.dev/viewer/?uri=github.com/apache/commons-codec)
The Apache Commons Codec component contains encoders and decoders for
formats such as Base16, Base32, Base64, digest, and Hexadecimal. In
addition to these
@@ -71,7 +71,7 @@ Alternatively, you can pull it from the central Maven
repositories:
<dependency>
<groupId>commons-codec</groupId>
<artifactId>commons-codec</artifactId>
- <version>1.22.1</version>
+ <version>1.23.0</version>
</dependency>
```
@@ -86,11 +86,11 @@ From a command shell, run `mvn` without arguments to invoke
the default Maven go
Contributing
------------
-We accept Pull Requests via GitHub. The [developer mailing
list](https://commons.apache.org/mail-lists.html) is the main channel of
communication for contributors.
+We accept pull requests via GitHub. The [developer mailing
list](https://commons.apache.org/mail-lists.html) is the main channel of
communication for contributors.
There are some guidelines which will make applying PRs easier for us:
+ No tabs! Please use spaces for indentation.
+ Respect the existing code style for each file.
-+ Create minimal diffs - disable on save actions like reformat source code or
organize imports. If you feel the source code should be reformatted create a
separate PR for this change.
++ Create minimal diffs: disable on-save actions like reformatting source code
or organizing imports. If you feel the source code should be reformatted,
create a separate PR for this change.
+ Provide JUnit tests for your changes and make sure your changes don't break
any existing tests by running `mvn`.
+ Before you push a PR, run `mvn` (without arguments). This runs the default
goal which contains all build checks.
+ To see the code coverage report, regardless of coverage failures, run `mvn
clean site -Dcommons.jacoco.haltOnFailure=false -Pjacoco`
diff --git a/RELEASE-NOTES.txt b/RELEASE-NOTES.txt
index f967ac22..39f14d40 100644
--- a/RELEASE-NOTES.txt
+++ b/RELEASE-NOTES.txt
@@ -1,3 +1,70 @@
+Apache Commons Codec 1.23.0 Release Notes
+-----------------------------------------
+
+The Apache Commons Codec team is pleased to announce the release of Apache
Commons Codec 1.23.0.
+
+The Apache Commons Codec component contains encoders and decoders for
+formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition
to these
+widely used encoders and decoders, the codec package also maintains a
+collection of phonetic encoding utilities.
+
+This is a feature and maintenance release. Java 8 or later is required.
+
+
+New features
+------------
+
+* Add and use PhoneticEngine.Builder and deprecate old
constructors. Thanks to Gary Gregory.
+* Add BeiderMorseEncoder.Builder and deprecate old constructor.
Thanks to Gary Gregory.
+* Add PhoneticEngine.Builder.setMaxInputLength(int). Thanks to Yu
Bao, Gary Gregory.
+* Add Base45 support. Thanks to Gary Gregory.
+* Add URLCodec.decodeUrl(BitSet, byte[]) to decode with a custom
safe set. Thanks to Gary Gregory.
+
+Fixed Bugs
+----------
+
+* GitIdentifiers orders tree entries by unsigned UTF-8 bytes, as
Git does, instead of UTF-16 code units. Thanks to Jeff Lenamon.
+* Optimize PhoneticEngine.encode(String, LanguageSet) for speed.
Thanks to Yu Bao, Gary Gregory.
+* RFC1522Codec.decodeText(String) now throws a DecoderException
instead of a StringIndexOutOfBoundsException when a separator is missing.
Thanks to Yu Bao, Gary Gregory.
+* Optimize Base58.convertFromBase58(byte[], Context) for speed and
temporary object allocation. Thanks to Yu Bao, Gary Gregory.
+* Allocate a single MessageDigest and use it in
Sha2Crypt.sha2Crypt(byte[], String, String, int, String). Thanks to Yu Bao,
Gary Gregory.
+* Javadoc improvements. Thanks to Gary Gregory.
+* Throw IOException instead of IllegalArgumentException in
BaseNCodecOutputStream and BaseNCodecOutputStream IO methods. Thanks to Gary
Gregory.
+* Throw DecoderException instead of IllegalArgumentException in
RFC1522Codec.decodeText(String). Thanks to Gary Gregory.
+* Fix Blake3 KDF example and clarify finalization semantics.
Thanks to Gary Gregory.
+* Base32 and Base64 STRICT decoding now require the encoder's
canonical alphabet, padding, and line separators, and validate streams through
EOF. Use LENIENT to retain permissive decoding. Thanks to Gary Gregory.
+* Limit Base58 decoding to 8192 encoded bytes by default, checking
cumulative stream input before buffering. Use
Base58.Builder.setMaxDecodeLength(int) for larger trusted input. Encoding
defaults to a configurable 8192-byte binary input limit through
Base58.Builder.setMaxEncodeLength(int). Thanks to Gary Gregory.
+* Grow Base58 accumulation buffers geometrically within the
configured input limits and validate actual accumulated length. Thanks to Gary
Gregory.
+* Implement Base58 encoded-length calculation and explicitly
reject unsupported line chunking. Thanks to Gary Gregory.
+* Close the underlying BaseNCodecOutputStream output even when
final conversion or flushing fails, preserving suppressed close exceptions.
Thanks to Gary Gregory.
+* Reject invalid GitIdentifiers tree entry names and
file/directory name conflicts to prevent ambiguous tree serialization and
colliding identifiers. Thanks to Gary Gregory.
+* Hex decoding now accepts only ASCII hexadecimal characters (0-9,
A-F, a-f). Previously accepted non-ASCII Unicode digits and fullwidth letters
now cause DecoderException, including when supplied as UTF-8 bytes or
ByteBuffers. Thanks to Gary Gregory.
+* Restrict Hex decoding to ASCII hexadecimal characters. Thanks to
Gary Gregory.
+* Validate BinaryCodec input while preserving leading-bit
truncation. Thanks to Gary Gregory.
+* Reject oversized Beider-Morse input before language guessing.
Thanks to Gary Gregory.
+* QuotedPrintableCodec decoding now preserves hard CRLF line
breaks and, leniently, unpaired CR and LF bytes instead of discarding them.
Soft line breaks require the full =CRLF sequence; previously accepted =CR
without LF now throws DecoderException. This affects both constructor modes and
QCodec, which shares the decoder. Thanks to Gary Gregory.
+* Bound Sha2Crypt rounds from caller-supplied salts. Thanks to
Gary Gregory.
+* Bound Sha2Crypt password length to prevent quadratic CPU DoS.
Thanks to Gary Gregory.
+* Make the @param names in BaseNCodec match the parameters they
document (#444). Thanks to geonseok, Gary Gregory.
+* CODEC-345: Restore URLCodec.encodeUrl(BitSet, byte[]) support for custom
safe sets containing percent and plus, and document the decoding limitations.
Thanks to Ganesh Gautam, Gary Gregory.
+* CODEC-245: Reject malformed Sha2Crypt salt syntax (#445). Thanks to Efe,
Gary Gregory.
+
+Changes
+-------
+
+* Bump org.apache.commons:commons-parent from 103 to 105. Thanks
to Gary Gregory.
+* [test] Bump org.apache.commons:commons-lang3 from 3.20.0 to
3.21.0 Thanks to Gary Gregory.
+
+
+For complete information on Apache Commons Codec, including instructions on
how to submit bug reports,
+patches, or suggestions for improvement, see the Apache Commons Codec website:
+
+https://commons.apache.org/proper/commons-codec/
+
+Download page:
https://commons.apache.org/proper/commons-codec/download_codec.cgi
+
+---------------------------------------------------------------------------------
+
Apache Commons Codec 1.22.1 Release Notes
-----------------------------------------
diff --git a/src/changes/changes.xml b/src/changes/changes.xml
index 0bad5cbc..25439e3e 100644
--- a/src/changes/changes.xml
+++ b/src/changes/changes.xml
@@ -43,7 +43,7 @@ The <action> type attribute can be add,update,fix,remove.
<author>Apache Commons Developers</author>
</properties>
<body>
- <release version="1.23.0" date="YYYY-MM-DD" description="This is a feature
and maintenance release. Java 8 or later is required.">
+ <release version="1.23.0" date="2026-10-04" description="This is a feature
and maintenance release. Java 8 or later is required.">
<!-- FIX -->
<action type="fix" dev="ggregory" due-to="Jeff Lenamon">GitIdentifiers
orders tree entries by unsigned UTF-8 bytes, as Git does, instead of UTF-16
code units.</action>
<action type="fix" dev="ggregory" due-to="Yu Bao, Gary Gregory">Optimize
PhoneticEngine.encode(String, LanguageSet) for speed.</action>
diff --git a/src/site/xdoc/download_codec.xml b/src/site/xdoc/download_codec.xml
index 1a78286c..f1eb318b 100644
--- a/src/site/xdoc/download_codec.xml
+++ b/src/site/xdoc/download_codec.xml
@@ -106,7 +106,7 @@ limitations under the License.
It is essential that you
<a href="https://www.apache.org/info/verification.html">verify the
integrity</a>
of downloaded files, preferably using the <code>PGP</code> signature
(<code>*.asc</code> files);
- failing that using the <code>SHA512</code> hash (<code>*.sha512</code>
checksum files).
+ failing that, using the <code>SHA512</code> hash
(<code>*.sha512</code> checksum files).
</p>
<p>
The <a href="https://downloads.apache.org/commons/KEYS">KEYS</a>
@@ -115,32 +115,32 @@ limitations under the License.
</p>
</subsection>
</section>
- <section name="Apache Commons Codec 1.22.1 ">
+ <section name="Apache Commons Codec 1.23.0 ">
<subsection name="Binaries">
<table>
<tr>
- <td><a
href="[preferred]/commons/codec/binaries/commons-codec-1.22.1-bin.tar.gz">commons-codec-1.22.1-bin.tar.gz</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.tar.gz.sha512">sha512</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.tar.gz.asc">pgp</a></td>
+ <td><a
href="[preferred]/commons/codec/binaries/commons-codec-1.23.0-bin.tar.gz">commons-codec-1.23.0-bin.tar.gz</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.tar.gz.sha512">sha512</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.tar.gz.asc">pgp</a></td>
</tr>
<tr>
- <td><a
href="[preferred]/commons/codec/binaries/commons-codec-1.22.1-bin.zip">commons-codec-1.22.1-bin.zip</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.zip.sha512">sha512</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.zip.asc">pgp</a></td>
+ <td><a
href="[preferred]/commons/codec/binaries/commons-codec-1.23.0-bin.zip">commons-codec-1.23.0-bin.zip</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.zip.sha512">sha512</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.zip.asc">pgp</a></td>
</tr>
</table>
</subsection>
<subsection name="Source">
<table>
<tr>
- <td><a
href="[preferred]/commons/codec/source/commons-codec-1.22.1-src.tar.gz">commons-codec-1.22.1-src.tar.gz</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.tar.gz.sha512">sha512</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.tar.gz.asc">pgp</a></td>
+ <td><a
href="[preferred]/commons/codec/source/commons-codec-1.23.0-src.tar.gz">commons-codec-1.23.0-src.tar.gz</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.tar.gz.sha512">sha512</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.tar.gz.asc">pgp</a></td>
</tr>
<tr>
- <td><a
href="[preferred]/commons/codec/source/commons-codec-1.22.1-src.zip">commons-codec-1.22.1-src.zip</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.zip.sha512">sha512</a></td>
- <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.zip.asc">pgp</a></td>
+ <td><a
href="[preferred]/commons/codec/source/commons-codec-1.23.0-src.zip">commons-codec-1.23.0-src.zip</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.zip.sha512">sha512</a></td>
+ <td><a
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.zip.asc">pgp</a></td>
</tr>
</table>
</subsection>
diff --git a/src/site/xdoc/issue-tracking.xml b/src/site/xdoc/issue-tracking.xml
index 6da5f6ed..23ed37b7 100644
--- a/src/site/xdoc/issue-tracking.xml
+++ b/src/site/xdoc/issue-tracking.xml
@@ -57,19 +57,19 @@ limitations under the License.
</p>
<p>
- To use JIRA you may need to <a
href="https://issues.apache.org/jira/secure/Signup!default.jspa">create an
account</a>
- (if you have previously created/updated Commons issues using Bugzilla an
account will have been automatically
+ To use JIRA, you may need to <a
href="https://issues.apache.org/jira/secure/Signup!default.jspa">create an
account</a>
+ (if you have previously created/updated Commons issues using Bugzilla,
an account will have been automatically
created and you can use the <a
href="https://issues.apache.org/jira/secure/ForgotPassword!default.jspa">Forgot
Password</a>
page to get a new password).
</p>
<p>
If you would like to report a bug, or raise an enhancement request with
- Apache Commons Codec please do the following:
+ Apache Commons Codec, please do the following:
</p>
<ol>
<li><a
href="https://issues.apache.org/jira/secure/IssueNavigator.jspa?reset=true&pid=12310464&sorter/field=issuekey&sorter/order=DESC&status=1&status=3&status=4">Search
existing open bugs</a>.
- If you find your issue listed then please add a comment with your
details.</li>
+ If you find your issue listed, then please add a comment with your
details.</li>
<li><a href="mail-lists.html">Search the mailing list archive(s)</a>.
You may find your issue or idea has already been discussed.</li>
<li>Decide if your issue is a bug or an enhancement.</li>
@@ -87,7 +87,7 @@ limitations under the License.
</ul>
<p>
- For more information on creating patches see the
+ For more information on creating patches, see the
<a href="https://www.apache.org/dev/contributors.html">Apache
Contributors Guide</a>.
</p>