Author: ggregory
Date: Tue Oct 6 10:19:16 2026
New Revision: 88221
Log:
Publish commons-secure-xml 1.1.0 Release
Added:
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz.asc
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.asc
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz.sha512
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.sha512
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip.asc
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.asc
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip.sha512
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.sha512
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz.asc
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.asc
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz.sha512
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.sha512
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip.asc
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.asc
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip.sha512
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.sha512
Replaced:
release/commons/secure-xml/RELEASE-NOTES.txt
- copied unchanged from r88220,
dev/commons/secure-xml/1.1.0-RC1/RELEASE-NOTES.txt
Deleted:
dev/commons/secure-xml/1.1.0-RC1/RELEASE-NOTES.txt
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.asc
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.sha512
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.asc
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.sha512
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.asc
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.sha512
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.asc
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.sha512
Copied: release/commons/secure-xml/RELEASE-NOTES.txt (from r88220,
dev/commons/secure-xml/1.1.0-RC1/RELEASE-NOTES.txt)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ release/commons/secure-xml/RELEASE-NOTES.txt Tue Oct 6 10:19:16
2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/RELEASE-NOTES.txt)
@@ -0,0 +1,133 @@
+
+Licensed to the Apache Software Foundation (ASF) under one or more
+contributor license agreements. See the NOTICE file distributed with
+this work for additional information regarding copyright ownership.
+The ASF licenses this file to You under the Apache License, Version 2.0
+(the "License"); you may not use this file except in compliance with
+the License. You may obtain a copy of the License at
+
+https://www.apache.org/licenses/LICENSE-2.0
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+
+Apache Commons Secure XML 1.1.0 Release Notes
+---------------------------------------------
+
+The Apache Commons Secure XML team is pleased to announce the release of
Apache Commons Secure XML 1.1.0.
+
+Apache Commons Secure XML provides secure-by-default JAXP factory creation,
abstracting over
+implementation-specific XXE securing differences between the stock JDK and
external JAXP implementations
+(Android, Apache Xalan, Apache Xerces, Woodstox, Saxon-HE).
+
+Second release. Requires Java 8 or later.
+
+
+New features
+------------
+
+* COMMONSXML-18: Add helpers that return a secure, namespace-aware
DocumentBuilder, SAXParser or XMLReader directly, without the factory. Thanks
to Piotr P. Karwasz, Gary Gregory.
+
+Fixed Bugs
+----------
+
+* Fix the OpenRewrite migration recipe to target static
method calls instead of class references. Thanks to Gary Gregory.
+* Fix the OpenRewrite migration recipe to add a dependency on
org.apache.commons:commons-secure-xml:1.0.0. Thanks to Gary Gregory.
+* Fix rejection behavior of foreign Templates in
SAXTransformerFactory.newTransformerHandler. Thanks to Piotr P. Karwasz, Gary
Gregory.
+* Fix a NullPointerException when an XMLFilter with a
self-driven parent reader is parsed with a null InputSource. #86 Thanks to
Piotr P. Karwasz, Gary Gregory.
+* COMMONSXML-17: Keep a URIResolver already set on a Transformer when it is
wrapped, instead of replacing it with the resolver floor. Thanks to Piotr P.
Karwasz, Gary Gregory.
+* Create the Transformer of an XMLFilter eagerly and reuse it
for every parse. Thanks to Piotr P. Karwasz, Gary Gregory.
+* Report a stylesheet that produces no XMLFilter as a
TransformerConfigurationException instead of returning null. Thanks to Piotr P.
Karwasz, Gary Gregory.
+* General Javadoc and site documentation improvements. Thanks
to Gary Gregory.
+
+Changes
+-------
+
+* Bump org.apache.commons:commons-parent from 104 to 105.
Thanks to Gary Gregory.
+* Bump com.android.library from 8.6.1 to 9.4.0 in
/android-tests. Thanks to Piotr P. Karwasz, Gary Gregory.
+* Bump commons.graalvm.buildtools.version from 1.1.12 to
1.1.14 (#102). Thanks to Gary Gregory, Dependabot.
+* Bump androidx.test:runner from 1.5.2 to 1.7.0 in
/android-tests (#106). Thanks to Gary Gregory, Dependabot.
+* Bump com.android.library from 9.4.0 to 9.4.1 in
/android-tests (#107). Thanks to Gary Gregory, Dependabot.
+* Bump gradle-wrapper from 9.7.1 to 9.8.0 in /android-tests
(#108). Thanks to Gary Gregory, Dependabot.
+* Bump org.junit.jupiter:junit-jupiter-api from 5.10.2 to
5.14.4 on Android (#111). Thanks to Gary Gregory, Dependabot.
+
+
+Historical list of changes:
https://commons.apache.org/proper/commons-secure-xml//changes.html
+
+For complete information on Apache Commons Secure XML, including instructions
on how to submit bug reports,
+patches, or suggestions for improvement, see the Apache Commons Secure XML
website:
+
+https://commons.apache.org/proper/commons-secure-xml/
+
+Download page:
https://commons.apache.org/proper/commons-secure-xml//download_secure-xml.cgi
+
+Have fun!
+-Apache Commons Team
+
+-----------------------------------------------------------------------------
+
+Apache Commons Secure XML 1.0.0 Release Notes
+---------------------------------------------
+
+The Apache Commons Secure XML team is pleased to announce the release of
Apache Commons Secure XML 1.0.0.
+
+Apache Commons Secure XML provides secure-by-default JAXP factory creation,
abstracting over
+implementation-specific XXE securing differences between the stock JDK and
external JAXP implementations
+(Android, Apache Xalan, Apache Xerces, Woodstox, Saxon-HE).
+
+First release. Requires Java 8 or later.
+
+
+New features
+------------
+
+* This is the first release of Apache Commons Secure XML.
Thanks to Piotr P. Karwasz, Gary Gregory.
+* Add secure-by-default JAXP factory creation via
org.apache.commons.xml.secure, donated from the copernik-xml-factory project
(https://github.com/copernik-eu/copernik-xml-factory) and covering the stock
JDK, Android, Apache Xalan, Apache Xerces, Woodstox, and Saxon-HE. Thanks to
Piotr P. Karwasz, Gary Gregory.
+* COMMONSXML-9: Install a non-removable resolver floor on every resolver
channel (EntityResolver, LSResourceResolver, URIResolver, and XMLResolver),
routing caller-supplied resolvers through it as allow-lists. Thanks to Piotr P.
Karwasz, Gary Gregory.
+* Secure the SAXTransformerFactory extension surface
(TransformerHandler, TemplatesHandler, and XMLFilter) and
TransformerFactory.getAssociatedStylesheet. Thanks to Piotr P. Karwasz, Gary
Gregory.
+* Document the threat model on the project site, including
the denied-fetch contract and the supported runtime floor (OpenJDK 8 and
Android API 33 or later). Thanks to Piotr P. Karwasz, Jarek Potiuk, Gary
Gregory.
+* COMMONSXML-11: Add GitHub CI builds for Java 26 and 27-EA. Thanks to Gary
Gregory, Piotr P. Karwasz.
+* Mirror on each factory class every JAXP static factory
method, including the Java 9 newDefaultInstance and Java 13 newNSInstance
families, all usable on Java 8. Thanks to Piotr P. Karwasz, Gary Gregory.
+
+Fixed Bugs
+----------
+
+* COMMONSXML-10: Block XInclude (xi:include) href resolution by default,
since the JAXP external-access properties do not govern it. Thanks to Ta Duc
Thien, Piotr P. Karwasz, Gary Gregory.
+* Honor jdk.xml.overrideDefaultParser on TrAX, XPath and
schema factories that recognize it. Thanks to Piotr P. Karwasz, Gary Gregory.
+* Restore the secure configuration when reset() is called on
a factory or parser instead of reverting to the implementation defaults. Thanks
to Piotr P. Karwasz, Gary Gregory.
+* Parse a Source opted in by a caller-supplied URIResolver
using a secure parser. Thanks to Piotr P. Karwasz, Gary Gregory.
+* Secure the document parse behind the InputSource-taking
XPath evaluation entry points. Thanks to Piotr P. Karwasz, Gary Gregory.
+* Fall back to the standard factory lookup in the DOM, SAX
and schema newDefaultInstance methods on Android. Thanks to Piotr P. Karwasz,
Gary Gregory.
+* Delegate the XPathFactory setProperty and getProperty
methods introduced in Java 18, so the implementation's properties stay
reachable on a secure factory. Thanks to Piotr P. Karwasz, Gary Gregory.
+* Bound the content model a schema expands into, so a compact
schema with a large maxOccurs cannot exhaust memory or CPU during validation.
Thanks to Piotr P. Karwasz, Gary Gregory.
+
+Changes
+-------
+
+* COMMONSXML-1,COMMONSXML-5,COMMONSXML-6,COMMONSXML-7,COMMONSXML-8: Recognize
XML implementations by the JAXP features and properties they support instead of
by their implementation class name, extending the securing to any compliant
implementation. Thanks to Piotr P. Karwasz, Gary Gregory.
+* COMMONSXML-4: Define a consistent contract for denied external fetches:
unresolved external references resolve to empty content on every
implementation, unless the org.apache.commons.xml.secure.throwOnUnresolved
system property requests rejection. Thanks to Piotr P. Karwasz, Gary Gregory.
+* COMMONSXML-3: Reduce the shaded footprint by splitting the secure classes
and resolver floors into independent entry points. Thanks to Piotr P. Karwasz,
Gary Gregory.
+* Allow the JAXP 1.5 accessExternal properties to be modified
on secured factories. Thanks to Piotr P. Karwasz, Gary Gregory.
+* Clean up the code and documentation after a review. Thanks
to Elliotte Rusty Harold, Piotr P. Karwasz.
+
+Removed
+-------
+
+* COMMONSXML-2: Remove the Limits class that applied uniform processing
limits across implementations. Thanks to Piotr P. Karwasz, Gary Gregory.
+
+Historical list of changes:
https://commons.apache.org/proper/commons-secure-xml//changes.html
+
+For complete information on Apache Commons Secure XML, including instructions
on how to submit bug reports,
+patches, or suggestions for improvement, see the Apache Commons Secure XML
website:
+
+https://commons.apache.org/proper/commons-secure-xml/
+
+Download page:
https://commons.apache.org/proper/commons-secure-xml/download_secure-xml.cgi
+
+Have fun!
+-Apache Commons Team
+
+-----------------------------------------------------------------------------
Copied: release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz)
==============================================================================
Binary file (source and/or target). No diff available.
Copied:
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz.asc
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.asc)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz.asc
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.asc)
@@ -0,0 +1,8 @@
+-----BEGIN PGP SIGNATURE-----
+
+iJEEABYKADkWIQT03VnJAUi9xSvrkKRTCqXyXCUBHwUCasBnCBsUgAAAAAAEAA5t
+YW51MiwyLjUrMS4xMiwwLDMACgkQUwql8lwlAR8qqAEAjFHfUex/i0px2LTdcZIA
+y9YJEo1XTnuFtqAuaoslH0gA/2zFI290WOWx2o0QjZZVb9Vllr9IIgGTswwyf0ic
+mHgN
+=rT95
+-----END PGP SIGNATURE-----
Copied:
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz.sha512
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.sha512)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.tar.gz.sha512
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.tar.gz.sha512)
@@ -0,0 +1 @@
+3c5337624100592624a589317c1bcac13a699f8a0735b7c378739c18394dd94eb8900753176f9f8d352ca153345d6510b24c12849a6fdcff2ec993ef6bdbb97f
Copied: release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip)
==============================================================================
Binary file (source and/or target). No diff available.
Copied:
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip.asc (from
r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.asc)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip.asc
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.asc)
@@ -0,0 +1,8 @@
+-----BEGIN PGP SIGNATURE-----
+
+iJEEABYKADkWIQT03VnJAUi9xSvrkKRTCqXyXCUBHwUCasBnCBsUgAAAAAAEAA5t
+YW51MiwyLjUrMS4xMiwwLDMACgkQUwql8lwlAR+m6AEAlWdmglVJYMYcLMgsu4em
+WTBq22VaBD9jWc2AUM6CXVcBAN7PxMv6IucGf+S/C2GMEeZYwFrAgVUo0oObyznL
+oMEO
+=pFAf
+-----END PGP SIGNATURE-----
Copied:
release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip.sha512
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.sha512)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ release/commons/secure-xml/binaries/commons-secure-xml-1.1.0-bin.zip.sha512
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/binaries/commons-secure-xml-1.1.0-bin.zip.sha512)
@@ -0,0 +1 @@
+9b20b8a2cf27ccf392792914353802edbbe5b139a1333cd6bb50c7c482a45b0a20731fc62b67d29410f59f1ff02fe299c93f56e3cdfeee0dec16f0a83a14d881
Copied: release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz)
==============================================================================
Binary file (source and/or target). No diff available.
Copied:
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz.asc (from
r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.asc)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz.asc
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.asc)
@@ -0,0 +1,8 @@
+-----BEGIN PGP SIGNATURE-----
+
+iJEEABYKADkWIQT03VnJAUi9xSvrkKRTCqXyXCUBHwUCasBnCBsUgAAAAAAEAA5t
+YW51MiwyLjUrMS4xMiwwLDMACgkQUwql8lwlAR8nlwEAmACieJDXXIofZCcayoBH
+3bxCReh79T6YaqLcgVfTu44A/1+NrmT7fWPjk1Lyr4VjL8oKXYV+mHbbe6XT7ZFP
+pdUC
+=pNVF
+-----END PGP SIGNATURE-----
Copied:
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz.sha512
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.sha512)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.tar.gz.sha512
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.tar.gz.sha512)
@@ -0,0 +1 @@
+cfe99526c45f9964bd5d89f9a10e50054072aba64b1f693d8901e6674010fcd4fe4abd2da24e8e1e8d9a822fdcd49b4fb64b4b960c6a6e7d453d6dbd6b000ebc
Copied: release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip)
==============================================================================
Binary file (source and/or target). No diff available.
Copied: release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip.asc
(from r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.asc)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip.asc
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.asc)
@@ -0,0 +1,8 @@
+-----BEGIN PGP SIGNATURE-----
+
+iJEEABYKADkWIQT03VnJAUi9xSvrkKRTCqXyXCUBHwUCasBnCBsUgAAAAAAEAA5t
+YW51MiwyLjUrMS4xMiwwLDMACgkQUwql8lwlAR+YxQEAyhxsI+Y71+tv3qd8H8dc
+truGioLjpi7tRMLSxMzjVO0BAO5H/X6QbLhAmukBGgz0wqFgEZ2yr93v+6ADPyEJ
+v3cO
+=LR2U
+-----END PGP SIGNATURE-----
Copied:
release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip.sha512 (from
r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.sha512)
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ release/commons/secure-xml/source/commons-secure-xml-1.1.0-src.zip.sha512
Tue Oct 6 10:19:16 2026 (r88221, copy of r88220,
dev/commons/secure-xml/1.1.0-RC1/source/commons-secure-xml-1.1.0-src.zip.sha512)
@@ -0,0 +1 @@
+0960817254e138d060baa9f574cdebaa88a3d5672d7a302ea7387922021eea11d106360fbe3cabffa27ea00846619dd35c2f864da9e0029ab518981dd6e33eb1