This is an automated email from the ASF dual-hosted git repository.

garydgregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-codec.git


The following commit(s) were added to refs/heads/master by this push:
     new d7bff678 Prepare for the release candidate
d7bff678 is described below

commit d7bff678de1efdf767f713c5a178ba9dd9e1562d
Author: Gary Gregory <[email protected]>
AuthorDate: Sun Oct 4 12:59:30 2026 +0000

    Prepare for the release candidate
---
 CONTRIBUTING.md                  | 26 ++++++++--------
 README.md                        | 10 +++---
 RELEASE-NOTES.txt                | 67 ++++++++++++++++++++++++++++++++++++++++
 src/changes/changes.xml          |  2 +-
 src/site/xdoc/download_codec.xml | 28 ++++++++---------
 src/site/xdoc/issue-tracking.xml | 10 +++---
 6 files changed, 105 insertions(+), 38 deletions(-)

diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 30a2a525..7d619927 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -41,35 +41,35 @@
 Contributing to Apache Commons Codec
 ======================
 
-Have you found a bug or have an idea for a cool new feature? Contributing code 
is a great way to give something back to the open-source community.
-Before you dig right into the code, we need contributors to follow a few 
guidelines to have a chance of keeping on top of things.
+Have you found a bug, or do you have an idea for a cool new feature? 
Contributing code is a great way to give something back to the open-source 
community.
+Before you dig right into the code, please review these guidelines to help us 
manage contributions.
 
 Getting Started
 ---------------
 
 + Make sure you have a [JIRA account](https://issues.apache.org/jira/).
-+ Make sure you have a [GitHub account](https://github.com/signup/free). This 
is not essential, but makes providing patches much easier.
-+ If you're planning to implement a new feature it makes sense to discuss your 
changes on the [dev list](https://commons.apache.org/mail-lists.html) first. 
This way you can make sure you're not wasting your time on something that isn't 
considered to be in Apache Commons Codec's scope.
++ Make sure you have a [GitHub account](https://github.com/signup). This is 
not essential, but it makes providing patches much easier.
++ If you're planning to implement a new feature, it makes sense to discuss 
your changes on the [dev list](https://commons.apache.org/mail-lists.html) 
first. This way you can make sure you're not wasting your time on something 
that isn't considered to be in Apache Commons Codec's scope.
 + Submit a [Jira Ticket][jira] for your issue, assuming one does not already 
exist.
-  + Clearly describe the issue including steps to reproduce when it is a bug.
+  + Clearly describe the issue, including steps to reproduce it if it is a bug.
   + Make sure you fill in the earliest version that you know has the issue.
 + Find the corresponding [repository on 
GitHub](https://github.com/apache/?query=commons-),
-[fork](https://help.github.com/articles/fork-a-repo/) and check out your 
forked repository. If you don't have a GitHub account, you can still clone the 
Commons repository.
+[fork](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/fork-a-repo)
 and check out your forked repository. If you don't have a GitHub account, you 
can still clone the Commons repository.
 
 Making Changes
 --------------
 
 + Create a _topic branch_ for your isolated work.
-  * Usually you should base your branch from the `master` branch.
-  * A good topic branch name can be the JIRA bug ID plus a keyword, e.g. 
`CODEC-123-InputStream`.
+  * Usually, you should base your branch on the `master` branch.
+  * A good topic branch name can be the JIRA bug ID plus a keyword, e.g., 
`CODEC-123-InputStream`.
   * If you have submitted multiple JIRA issues, try to maintain separate 
branches and pull requests.
 + Make commits of logical units.
   * Make sure your commit messages are meaningful and in the proper format. 
Your commit message should contain the key of the JIRA issue.
   * For example, `[CODEC-123] Close input stream sooner`
 + Respect the original code style:
   + Only use spaces for indentation; you can check for unnecessary whitespace 
with `git diff` before committing.
-  + Create minimal diffs - disable _On Save_ actions like _Reformat Source 
Code_ or _Organize Imports_. If you feel the source code should be reformatted 
create a separate PR for this change first.
-+ Write unit tests that match behavioral changes, where the tests fail if the 
changes to the runtime are not applied. This may not always be possible but is 
a best practice.
+  + Create minimal diffs: disable _On Save_ actions like _Reformat Source 
Code_ or _Organize Imports_. If you feel the source code should be reformatted, 
create a separate PR for this change first.
++ Write unit tests that match behavioral changes, where the tests fail if the 
changes to the runtime are not applied. This may not always be possible, but it 
is a best practice.
 Unit tests are typically in the `src/test/java` directory.
 + Run a successful build using the default [Maven](https://maven.apache.org/) 
goal with `mvn`; that's `mvn` on the command line by itself.
 + Write a pull request description that is detailed enough to understand what 
the pull request does, how, and why.
@@ -95,7 +95,7 @@ Submitting Changes
 + Push your changes to a topic branch in your fork of the repository.
 + Submit a _Pull Request_ to the corresponding repository in the `apache` 
organization.
   * Verify _Files Changed_ shows only your intended changes and does not
-  include additional files like `target/*.class`
+  include additional files like `target/*.class`.
 + Update your JIRA ticket and include a link to the pull request in the ticket.
 
 If you prefer to not use GitHub, then you can instead use
@@ -108,8 +108,8 @@ Additional Resources
 + [Contributing patches](https://commons.apache.org/patches.html)
 + [Apache Commons Codec JIRA project page][jira]
 + [Contributor License Agreement][cla]
-+ [General GitHub documentation](https://help.github.com/)
-+ [GitHub pull request 
documentation](https://help.github.com/articles/creating-a-pull-request/)
++ [General GitHub documentation](https://docs.github.com/)
++ [GitHub pull request 
documentation](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/creating-a-pull-request)
 
 [cla]:https://www.apache.org/licenses/#clas
 [jira]:https://issues.apache.org/jira/browse/CODEC
diff --git a/README.md b/README.md
index d796d483..ad3f405e 100644
--- a/README.md
+++ b/README.md
@@ -45,9 +45,9 @@ Apache Commons Codec
 
 [![Java 
CI](https://github.com/apache/commons-codec/actions/workflows/maven.yml/badge.svg)](https://github.com/apache/commons-codec/actions/workflows/maven.yml)
 [![Maven 
Central](https://img.shields.io/maven-central/v/commons-codec/commons-codec?label=Maven%20Central)](https://search.maven.org/artifact/commons-codec/commons-codec)
-[![Javadocs](https://javadoc.io/badge/commons-codec/commons-codec/1.22.1.svg)](https://javadoc.io/doc/commons-codec/commons-codec/1.22.1)
+[![Javadocs](https://javadoc.io/badge/commons-codec/commons-codec/1.23.0.svg)](https://javadoc.io/doc/commons-codec/commons-codec/1.23.0)
 
[![CodeQL](https://github.com/apache/commons-codec/actions/workflows/codeql-analysis.yml/badge.svg)](https://github.com/apache/commons-codec/actions/workflows/codeql-analysis.yml)
-[![OpenSSF 
Scorecard](https://api.securityscorecards.dev/projects/github.com/apache/commons-codec/badge)](https://api.securityscorecards.dev/projects/github.com/apache/commons-codec)
+[![OpenSSF 
Scorecard](https://api.securityscorecards.dev/projects/github.com/apache/commons-codec/badge)](https://scorecard.dev/viewer/?uri=github.com/apache/commons-codec)
 
 The Apache Commons Codec component contains encoders and decoders for
      formats such as Base16, Base32, Base64, digest, and Hexadecimal. In 
addition to these
@@ -71,7 +71,7 @@ Alternatively, you can pull it from the central Maven 
repositories:
 <dependency>
   <groupId>commons-codec</groupId>
   <artifactId>commons-codec</artifactId>
-  <version>1.22.1</version>
+  <version>1.23.0</version>
 </dependency>
 ```
 
@@ -86,11 +86,11 @@ From a command shell, run `mvn` without arguments to invoke 
the default Maven go
 Contributing
 ------------
 
-We accept Pull Requests via GitHub. The [developer mailing 
list](https://commons.apache.org/mail-lists.html) is the main channel of 
communication for contributors.
+We accept pull requests via GitHub. The [developer mailing 
list](https://commons.apache.org/mail-lists.html) is the main channel of 
communication for contributors.
 There are some guidelines which will make applying PRs easier for us:
 + No tabs! Please use spaces for indentation.
 + Respect the existing code style for each file.
-+ Create minimal diffs - disable on save actions like reformat source code or 
organize imports. If you feel the source code should be reformatted create a 
separate PR for this change.
++ Create minimal diffs: disable on-save actions like reformatting source code 
or organizing imports. If you feel the source code should be reformatted, 
create a separate PR for this change.
 + Provide JUnit tests for your changes and make sure your changes don't break 
any existing tests by running `mvn`.
 + Before you push a PR, run `mvn` (without arguments). This runs the default 
goal which contains all build checks.
 + To see the code coverage report, regardless of coverage failures, run `mvn 
clean site -Dcommons.jacoco.haltOnFailure=false -Pjacoco`
diff --git a/RELEASE-NOTES.txt b/RELEASE-NOTES.txt
index f967ac22..39f14d40 100644
--- a/RELEASE-NOTES.txt
+++ b/RELEASE-NOTES.txt
@@ -1,3 +1,70 @@
+Apache Commons Codec 1.23.0 Release Notes
+-----------------------------------------
+
+The Apache Commons Codec team is pleased to announce the release of Apache 
Commons Codec 1.23.0.
+
+The Apache Commons Codec component contains encoders and decoders for
+formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition 
to these
+widely used encoders and decoders, the codec package also maintains a
+collection of phonetic encoding utilities.
+
+This is a feature and maintenance release. Java 8 or later is required.
+
+
+New features
+------------
+
+*             Add and use PhoneticEngine.Builder and deprecate old 
constructors. Thanks to Gary Gregory.
+*             Add BeiderMorseEncoder.Builder and deprecate old constructor. 
Thanks to Gary Gregory.
+*             Add PhoneticEngine.Builder.setMaxInputLength(int). Thanks to Yu 
Bao, Gary Gregory.
+*             Add Base45 support. Thanks to Gary Gregory.
+*             Add URLCodec.decodeUrl(BitSet, byte[]) to decode with a custom 
safe set. Thanks to Gary Gregory.
+
+Fixed Bugs
+----------
+
+*             GitIdentifiers orders tree entries by unsigned UTF-8 bytes, as 
Git does, instead of UTF-16 code units. Thanks to Jeff Lenamon.
+*             Optimize PhoneticEngine.encode(String, LanguageSet) for speed. 
Thanks to Yu Bao, Gary Gregory.
+*             RFC1522Codec.decodeText(String) now throws a DecoderException 
instead of a StringIndexOutOfBoundsException when a separator is missing. 
Thanks to Yu Bao, Gary Gregory.
+*             Optimize Base58.convertFromBase58(byte[], Context) for speed and 
temporary object allocation. Thanks to Yu Bao, Gary Gregory.
+*             Allocate a single MessageDigest and use it in 
Sha2Crypt.sha2Crypt(byte[], String, String, int, String). Thanks to Yu Bao, 
Gary Gregory.
+*             Javadoc improvements. Thanks to Gary Gregory.
+*             Throw IOException instead of IllegalArgumentException in 
BaseNCodecOutputStream and BaseNCodecOutputStream IO methods. Thanks to Gary 
Gregory.
+*             Throw DecoderException instead of IllegalArgumentException in 
RFC1522Codec.decodeText(String). Thanks to Gary Gregory.
+*             Fix Blake3 KDF example and clarify finalization semantics. 
Thanks to Gary Gregory.
+*             Base32 and Base64 STRICT decoding now require the encoder's 
canonical alphabet, padding, and line separators, and validate streams through 
EOF. Use LENIENT to retain permissive decoding. Thanks to Gary Gregory.
+*             Limit Base58 decoding to 8192 encoded bytes by default, checking 
cumulative stream input before buffering. Use 
Base58.Builder.setMaxDecodeLength(int) for larger trusted input. Encoding 
defaults to a configurable 8192-byte binary input limit through 
Base58.Builder.setMaxEncodeLength(int). Thanks to Gary Gregory.
+*             Grow Base58 accumulation buffers geometrically within the 
configured input limits and validate actual accumulated length. Thanks to Gary 
Gregory.
+*             Implement Base58 encoded-length calculation and explicitly 
reject unsupported line chunking. Thanks to Gary Gregory.
+*             Close the underlying BaseNCodecOutputStream output even when 
final conversion or flushing fails, preserving suppressed close exceptions. 
Thanks to Gary Gregory.
+*             Reject invalid GitIdentifiers tree entry names and 
file/directory name conflicts to prevent ambiguous tree serialization and 
colliding identifiers. Thanks to Gary Gregory.
+*             Hex decoding now accepts only ASCII hexadecimal characters (0-9, 
A-F, a-f). Previously accepted non-ASCII Unicode digits and fullwidth letters 
now cause DecoderException, including when supplied as UTF-8 bytes or 
ByteBuffers. Thanks to Gary Gregory.
+*             Restrict Hex decoding to ASCII hexadecimal characters. Thanks to 
Gary Gregory.
+*             Validate BinaryCodec input while preserving leading-bit 
truncation. Thanks to Gary Gregory.
+*             Reject oversized Beider-Morse input before language guessing. 
Thanks to Gary Gregory.
+*             QuotedPrintableCodec decoding now preserves hard CRLF line 
breaks and, leniently, unpaired CR and LF bytes instead of discarding them. 
Soft line breaks require the full =CRLF sequence; previously accepted =CR 
without LF now throws DecoderException. This affects both constructor modes and 
QCodec, which shares the decoder. Thanks to Gary Gregory.
+*             Bound Sha2Crypt rounds from caller-supplied salts. Thanks to 
Gary Gregory.
+*             Bound Sha2Crypt password length to prevent quadratic CPU DoS. 
Thanks to Gary Gregory.
+*             Make the @param names in BaseNCodec match the parameters they 
document (#444). Thanks to geonseok, Gary Gregory.
+* CODEC-345:  Restore URLCodec.encodeUrl(BitSet, byte[]) support for custom 
safe sets containing percent and plus, and document the decoding limitations. 
Thanks to Ganesh Gautam, Gary Gregory.
+* CODEC-245:  Reject malformed Sha2Crypt salt syntax (#445). Thanks to Efe, 
Gary Gregory.
+
+Changes
+-------
+
+*             Bump org.apache.commons:commons-parent from 103 to 105. Thanks 
to Gary Gregory.
+*             [test] Bump org.apache.commons:commons-lang3 from 3.20.0 to 
3.21.0 Thanks to Gary Gregory.
+
+
+For complete information on Apache Commons Codec, including instructions on 
how to submit bug reports,
+patches, or suggestions for improvement, see the Apache Commons Codec website:
+
+https://commons.apache.org/proper/commons-codec/
+
+Download page: 
https://commons.apache.org/proper/commons-codec/download_codec.cgi
+
+---------------------------------------------------------------------------------
+
 Apache Commons Codec 1.22.1 Release Notes
 -----------------------------------------
 
diff --git a/src/changes/changes.xml b/src/changes/changes.xml
index 0bad5cbc..25439e3e 100644
--- a/src/changes/changes.xml
+++ b/src/changes/changes.xml
@@ -43,7 +43,7 @@ The <action> type attribute can be add,update,fix,remove.
     <author>Apache Commons Developers</author>
   </properties>
   <body>
-    <release version="1.23.0" date="YYYY-MM-DD" description="This is a feature 
and maintenance release. Java 8 or later is required.">
+    <release version="1.23.0" date="2026-10-04" description="This is a feature 
and maintenance release. Java 8 or later is required.">
       <!-- FIX -->
       <action type="fix" dev="ggregory" due-to="Jeff Lenamon">GitIdentifiers 
orders tree entries by unsigned UTF-8 bytes, as Git does, instead of UTF-16 
code units.</action>
       <action type="fix" dev="ggregory" due-to="Yu Bao, Gary Gregory">Optimize 
PhoneticEngine.encode(String, LanguageSet) for speed.</action>
diff --git a/src/site/xdoc/download_codec.xml b/src/site/xdoc/download_codec.xml
index 1a78286c..f1eb318b 100644
--- a/src/site/xdoc/download_codec.xml
+++ b/src/site/xdoc/download_codec.xml
@@ -106,7 +106,7 @@ limitations under the License.
         It is essential that you
         <a href="https://www.apache.org/info/verification.html";>verify the 
integrity</a>
         of downloaded files, preferably using the <code>PGP</code> signature 
(<code>*.asc</code> files);
-        failing that using the <code>SHA512</code> hash (<code>*.sha512</code> 
checksum files).
+        failing that, using the <code>SHA512</code> hash 
(<code>*.sha512</code> checksum files).
       </p>
       <p>
         The <a href="https://downloads.apache.org/commons/KEYS";>KEYS</a>
@@ -115,32 +115,32 @@ limitations under the License.
       </p>
     </subsection>
     </section>
-    <section name="Apache Commons Codec 1.22.1 ">
+    <section name="Apache Commons Codec 1.23.0 ">
       <subsection name="Binaries">
         <table>
           <tr>
-              <td><a 
href="[preferred]/commons/codec/binaries/commons-codec-1.22.1-bin.tar.gz">commons-codec-1.22.1-bin.tar.gz</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.tar.gz.sha512";>sha512</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.tar.gz.asc";>pgp</a></td>
+              <td><a 
href="[preferred]/commons/codec/binaries/commons-codec-1.23.0-bin.tar.gz">commons-codec-1.23.0-bin.tar.gz</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.tar.gz.sha512";>sha512</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.tar.gz.asc";>pgp</a></td>
           </tr>
           <tr>
-              <td><a 
href="[preferred]/commons/codec/binaries/commons-codec-1.22.1-bin.zip">commons-codec-1.22.1-bin.zip</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.zip.sha512";>sha512</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.22.1-bin.zip.asc";>pgp</a></td>
+              <td><a 
href="[preferred]/commons/codec/binaries/commons-codec-1.23.0-bin.zip">commons-codec-1.23.0-bin.zip</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.zip.sha512";>sha512</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/binaries/commons-codec-1.23.0-bin.zip.asc";>pgp</a></td>
           </tr>
         </table>
       </subsection>
       <subsection name="Source">
         <table>
           <tr>
-              <td><a 
href="[preferred]/commons/codec/source/commons-codec-1.22.1-src.tar.gz">commons-codec-1.22.1-src.tar.gz</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.tar.gz.sha512";>sha512</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.tar.gz.asc";>pgp</a></td>
+              <td><a 
href="[preferred]/commons/codec/source/commons-codec-1.23.0-src.tar.gz">commons-codec-1.23.0-src.tar.gz</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.tar.gz.sha512";>sha512</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.tar.gz.asc";>pgp</a></td>
           </tr>
           <tr>
-              <td><a 
href="[preferred]/commons/codec/source/commons-codec-1.22.1-src.zip">commons-codec-1.22.1-src.zip</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.zip.sha512";>sha512</a></td>
-              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.22.1-src.zip.asc";>pgp</a></td>
+              <td><a 
href="[preferred]/commons/codec/source/commons-codec-1.23.0-src.zip">commons-codec-1.23.0-src.zip</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.zip.sha512";>sha512</a></td>
+              <td><a 
href="https://downloads.apache.org/commons/codec/source/commons-codec-1.23.0-src.zip.asc";>pgp</a></td>
           </tr>
         </table>
       </subsection>
diff --git a/src/site/xdoc/issue-tracking.xml b/src/site/xdoc/issue-tracking.xml
index 6da5f6ed..23ed37b7 100644
--- a/src/site/xdoc/issue-tracking.xml
+++ b/src/site/xdoc/issue-tracking.xml
@@ -57,19 +57,19 @@ limitations under the License.
       </p>
 
       <p>
-      To use JIRA you may need to <a 
href="https://issues.apache.org/jira/secure/Signup!default.jspa";>create an 
account</a>
-      (if you have previously created/updated Commons issues using Bugzilla an 
account will have been automatically
+      To use JIRA, you may need to <a 
href="https://issues.apache.org/jira/secure/Signup!default.jspa";>create an 
account</a>
+      (if you have previously created/updated Commons issues using Bugzilla, 
an account will have been automatically
       created and you can use the <a 
href="https://issues.apache.org/jira/secure/ForgotPassword!default.jspa";>Forgot 
Password</a>
       page to get a new password).
       </p>
 
       <p>
       If you would like to report a bug, or raise an enhancement request with
-      Apache Commons Codec please do the following:
+      Apache Commons Codec, please do the following:
       </p>
       <ol>
         <li><a 
href="https://issues.apache.org/jira/secure/IssueNavigator.jspa?reset=true&amp;pid=12310464&amp;sorter/field=issuekey&amp;sorter/order=DESC&amp;status=1&amp;status=3&amp;status=4";>Search
 existing open bugs</a>.
-            If you find your issue listed then please add a comment with your 
details.</li>
+            If you find your issue listed, then please add a comment with your 
details.</li>
         <li><a href="mail-lists.html">Search the mailing list archive(s)</a>.
             You may find your issue or idea has already been discussed.</li>
         <li>Decide if your issue is a bug or an enhancement.</li>
@@ -87,7 +87,7 @@ limitations under the License.
       </ul>
 
       <p>
-      For more information on creating patches see the
+      For more information on creating patches, see the
       <a href="https://www.apache.org/dev/contributors.html";>Apache 
Contributors Guide</a>.
       </p>
 

Reply via email to