Re: [PR] SLING-12147 Replace Sling XSS with OWASP Encoder [sling-org-apache-sling-caconfig-impl]

2023-11-13 Thread via GitHub
sonarcloud[bot] commented on PR #8: URL: https://github.com/apache/sling-org-apache-sling-caconfig-impl/pull/8#issuecomment-1808244803 SonarCloud Quality Gate failed. [![Quality Gate

Re: [VOTE] Release Apache Sling Repoinit JCR 1.1.46

2023-11-13 Thread Carsten Ziegeler
+1 Carsten On 13.11.2023 13:25, Julian Sedding wrote: Hi, We solved 3 issues in this release: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310710=12352870=Text Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2807/ You can use this

[VOTE] Release Apache Sling Repoinit JCR 1.1.46

2023-11-13 Thread Julian Sedding
Hi, We solved 3 issues in this release: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310710=12352870=Text Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2807/ You can use this UNIX script to download the release and verify the

[jira] [Resolved] (SLING-12140) Creating new jira version fails: No releases found in 'Parent 60 (Java 11)'

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12140?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu resolved SLING-12140. - Resolution: Fixed > Creating new jira version fails: No releases found in 'Parent 60

[jira] [Resolved] (SLING-12147) caconfig-impl: Replace Sling XSS with OWASP Encoder

2023-11-13 Thread Stefan Seifert (Jira)
[ https://issues.apache.org/jira/browse/SLING-12147?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Stefan Seifert resolved SLING-12147. Resolution: Fixed

Re: [PR] SLING-12147 Replace Sling XSS with OWASP Encoder [sling-org-apache-sling-caconfig-impl]

2023-11-13 Thread via GitHub
stefanseifert merged PR #8: URL: https://github.com/apache/sling-org-apache-sling-caconfig-impl/pull/8 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

Re: [VOTE] Release Apache Sling slingfeature maven plugin 1.8.0

2023-11-13 Thread Carsten Ziegeler
+1 Carsten On 13.11.2023 10:41, Carsten Ziegeler wrote: Hi, We solved 6 issues in the feature model https://issues.apache.org/jira/projects/SLING/versions/12353832 Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2806/ You can use this UNIX script to

[jira] [Created] (SLING-12147) caconfig-impl: Replace Sling XSS with OWASP Encoder

2023-11-13 Thread Stefan Seifert (Jira)
Stefan Seifert created SLING-12147: -- Summary: caconfig-impl: Replace Sling XSS with OWASP Encoder Key: SLING-12147 URL: https://issues.apache.org/jira/browse/SLING-12147 Project: Sling

Re: [VOTE] Release Apache Sling slingfeature maven plugin 1.8.0

2023-11-13 Thread Daniel Klco
+1 On Mon, Nov 13, 2023 at 7:22 AM Carsten Ziegeler wrote: > +1 > > Carsten > > On 13.11.2023 10:41, Carsten Ziegeler wrote: > > Hi, > > > > We solved 6 issues in the feature model > > https://issues.apache.org/jira/projects/SLING/versions/12353832 > > > > > > Staging repository: > >

RE: [VOTE] Release Apache Sling slingfeature maven plugin 1.8.0

2023-11-13 Thread Stefan Seifert
+1 stefan

RE: [VOTE] Release Apache Sling Repoinit JCR 1.1.46

2023-11-13 Thread Stefan Seifert
+1 stefan

Re: [PR] SLING-11352 - Fix parsing of path-only mappings [sling-org-apache-sling-resourceresolver]

2023-11-13 Thread via GitHub
sonarcloud[bot] commented on PR #84: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/84#issuecomment-1808922325 Kudos, SonarCloud Quality Gate passed! [![Quality Gate

Re: [PR] Various improvements for the webconsole plugin [sling-org-apache-sling-resourceresolver]

2023-11-13 Thread via GitHub
sonarcloud[bot] commented on PR #78: URL: https://github.com/apache/sling-org-apache-sling-resourceresolver/pull/78#issuecomment-1808923595 SonarCloud Quality Gate failed. [![Quality Gate

[PR] chore(deps): update dependency org.apache.sling:org.apache.sling.xss to v2.4.0 [sling-org-apache-sling-starter]

2023-11-13 Thread via GitHub
renovate-bot opened a new pull request, #273: URL: https://github.com/apache/sling-org-apache-sling-starter/pull/273 [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age |

[PR] chore(deps): update dependency org.apache.sling:org.apache.sling.resourceresolver to v1.11.2 [sling-org-apache-sling-starter]

2023-11-13 Thread via GitHub
renovate-bot opened a new pull request, #272: URL: https://github.com/apache/sling-org-apache-sling-starter/pull/272 [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age |

Re: [PR] chore(deps): update dependency org.apache.sling:org.apache.sling.xss to v2.4.0 [sling-site]

2023-11-13 Thread via GitHub
rombert merged PR #146: URL: https://github.com/apache/sling-site/pull/146 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[PR] chore(deps): update dependency org.apache.sling:org.apache.sling.xss to v2.4.0 [sling-site]

2023-11-13 Thread via GitHub
renovate-bot opened a new pull request, #146: URL: https://github.com/apache/sling-site/pull/146 [![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com) This PR contains the following updates: | Package | Change | Age | Adoption | Passing |

[jira] [Commented] (SLING-12152) IOException is not properly handled by error handling

2023-11-13 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-12152?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17785630#comment-17785630 ] Carsten Ziegeler commented on SLING-12152: -- Potential fix in

Re: [VOTE] Release Apache Sling Repoinit JCR 1.1.46

2023-11-13 Thread Jörg Hoh
+1 Am Mo., 13. Nov. 2023 um 13:25 Uhr schrieb Julian Sedding < jsedd...@gmail.com>: > Hi, > > We solved 3 issues in this release: > > https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310710=12352870=Text > > Staging repository: >

Re: [VOTE] Release Apache Sling slingfeature maven plugin 1.8.0

2023-11-13 Thread Jörg Hoh
+1 Am Mo., 13. Nov. 2023 um 10:41 Uhr schrieb Carsten Ziegeler < cziege...@apache.org>: > Hi, > > We solved 6 issues in the feature model > https://issues.apache.org/jira/projects/SLING/versions/12353832 > > > Staging repository: >

Re: [VOTE] Release Apache Sling Content Distribution Journal Messages 0.5.8

2023-11-13 Thread Christian Schneider
-1 In this version a link to distribution API is added. I think this should rather not be added in the messaging abstraction. Can someone explain the purpose and why it should belong in this api? Christian Am Sa., 11. Nov. 2023 um 22:40 Uhr schrieb Timothee Maret : > Hi, > > We solved 1 issues

[jira] [Created] (SLING-12146) Committer CLI build fails on Windows

2023-11-13 Thread Robert Munteanu (Jira)
Robert Munteanu created SLING-12146: --- Summary: Committer CLI build fails on Windows Key: SLING-12146 URL: https://issues.apache.org/jira/browse/SLING-12146 Project: Sling Issue Type: Bug

[jira] [Updated] (SLING-12146) Committer CLI build fails on Windows

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12146?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu updated SLING-12146: Attachment: committer-cli-windows.log > Committer CLI build fails on Windows >

[jira] [Resolved] (SLING-12115) Repoinit should leave importBehaviour for ACL creation to JCR

2023-11-13 Thread Julian Sedding (Jira)
[ https://issues.apache.org/jira/browse/SLING-12115?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Julian Sedding resolved SLING-12115. Resolution: Fixed > Repoinit should leave importBehaviour for ACL creation to JCR >

[jira] [Resolved] (SLING-12114) Update org.apache.sling.jcr.repoinit to parent pom 52

2023-11-13 Thread Julian Sedding (Jira)
[ https://issues.apache.org/jira/browse/SLING-12114?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Julian Sedding resolved SLING-12114. Resolution: Fixed > Update org.apache.sling.jcr.repoinit to parent pom 52 >

Re: [PR] SLING-12114 - Update org.apache.sling.jcr.repoinit to parent pom 52 [sling-org-apache-sling-jcr-repoinit]

2023-11-13 Thread via GitHub
jsedding merged PR #47: URL: https://github.com/apache/sling-org-apache-sling-jcr-repoinit/pull/47 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[PR] SLING-12114 - Update org.apache.sling.jcr.repoinit to parent pom 52 [sling-org-apache-sling-jcr-repoinit]

2023-11-13 Thread via GitHub
jsedding opened a new pull request, #47: URL: https://github.com/apache/sling-org-apache-sling-jcr-repoinit/pull/47 - update parent and dependencies - cleanup unused dependencies -- This is an automated message from the Apache Git Service. To respond to the message, please log on to

[VOTE] Release Apache Sling slingfeature maven plugin 1.8.0

2023-11-13 Thread Carsten Ziegeler
Hi, We solved 6 issues in the feature model https://issues.apache.org/jira/projects/SLING/versions/12353832 Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2806/ You can use this UNIX script to download the release and verify the signatures:

Re: [VOTE] Release Apache Sling Content Distribution Journal Messages 0.5.8

2023-11-13 Thread Timothée Maret
Indeed, an API is added. Purpose is to provide metadata to the package messages. Could you reconsider your veto please ? Cheers, Timothee Le lun. 13 nov. 2023 à 09:41, Christian Schneider a écrit : > -1 > In this version a link to distribution API is added. > I think this should rather not

[jira] [Updated] (SLING-12149) ResourceResolver: Illegal mode passthrough for resource provider null

2023-11-13 Thread Joerg Hoh (Jira)
[ https://issues.apache.org/jira/browse/SLING-12149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Joerg Hoh updated SLING-12149: -- Description: When trying the new ResourcResolver 1.11.2 I get this log message for many/all

[jira] [Updated] (SLING-12149) ResourceResolver: Illegal mode passthrough for resource provider null

2023-11-13 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-12149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler updated SLING-12149: - Fix Version/s: Resource Resolver 1.11.4 > ResourceResolver: Illegal mode passthrough

[jira] [Commented] (SLING-12148) Committer CLI Fails to Parse CI Status

2023-11-13 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-12148?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17785535#comment-17785535 ] Dan Klco commented on SLING-12148: -- Looks like the issue is due to a .git suffix when it extracts

[jira] [Closed] (SLING-12123) Unexpected new requirements for the XSS bundle

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12123?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-12123. --- > Unexpected new requirements for the XSS bundle >

[jira] [Closed] (SLING-11921) Building javadoc with Java 11 fails

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-11921?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-11921. --- > Building javadoc with Java 11 fails > --- > >

[jira] [Commented] (SLING-12151) Update o.a.f.cm.json to 2.0.2 to reduce OOM scenarios

2023-11-13 Thread Jira
[ https://issues.apache.org/jira/browse/SLING-12151?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17785566#comment-17785566 ] Dominik Süß commented on SLING-12151: - While testing the patch I discovered a potential regression

[jira] [Commented] (SLING-12149) ResourceResolver: Illegal mode passthrough for resource provider null

2023-11-13 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-12149?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17785532#comment-17785532 ] Carsten Ziegeler commented on SLING-12149: -- That's a regression caused by

[jira] [Created] (SLING-12150) Update to parent pom 52

2023-11-13 Thread Robert Munteanu (Jira)
Robert Munteanu created SLING-12150: --- Summary: Update to parent pom 52 Key: SLING-12150 URL: https://issues.apache.org/jira/browse/SLING-12150 Project: Sling Issue Type: Improvement

[jira] [Resolved] (SLING-12149) ResourceResolver: Illegal mode passthrough for resource provider null

2023-11-13 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-12149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler resolved SLING-12149. -- Resolution: Fixed Fixed in

[jira] [Created] (SLING-12151) Update o.a.f.cm.json to 2.0.2 to reduce OOM scenarios

2023-11-13 Thread Jira
Dominik Süß created SLING-12151: --- Summary: Update o.a.f.cm.json to 2.0.2 to reduce OOM scenarios Key: SLING-12151 URL: https://issues.apache.org/jira/browse/SLING-12151 Project: Sling Issue

[RESULT] [VOTE] Release Apache Sling XSS Protection API 2.4.0

2023-11-13 Thread Robert Munteanu
Hi, The vote has passed with the following result: +1 (binding): Carsten Ziegeler, Joerg Hoh, Eric Norman, Dan Klco +1 (non-binding): none I will copy this release to the Sling dist directory and promote the artifacts to the central Maven repository. Regards, Robert Munteanu

[jira] [Closed] (SLING-12137) XSS API bundle no longer embeds the needed org.owasp.html classes

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12137?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-12137. --- > XSS API bundle no longer embeds the needed org.owasp.html classes >

[jira] [Closed] (SLING-11882) XSS Protection API: Apply shading/package relocation to embedded Guava+Co Libraries

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-11882?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-11882. --- > XSS Protection API: Apply shading/package relocation to embedded Guava+Co > Libraries >

[jira] [Closed] (SLING-12118) Update Batik XML utility library to version 1.17

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12118?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-12118. --- > Update Batik XML utility library to version 1.17 >

[jira] [Closed] (SLING-12070) Migrate sling.xss to jakarta.json

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12070?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-12070. --- > Migrate sling.xss to jakarta.json > - > >

[jira] [Closed] (SLING-12116) Update transative google-guava dependency to version 32.1.3-jre

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12116?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-12116. --- > Update transative google-guava dependency to version 32.1.3-jre >

[jira] [Closed] (SLING-12005) XSS bundle should not embed org.owasp.encoder

2023-11-13 Thread Robert Munteanu (Jira)
[ https://issues.apache.org/jira/browse/SLING-12005?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Robert Munteanu closed SLING-12005. --- > XSS bundle should not embed org.owasp.encoder > -

Re: [VOTE] Release Apache Sling Repoinit JCR 1.1.46

2023-11-13 Thread Daniel Klco
+1 On Mon, Nov 13, 2023 at 9:22 AM Carsten Ziegeler wrote: > +1 > > Carsten > > On 13.11.2023 13:25, Julian Sedding wrote: > > Hi, > > > > We solved 3 issues in this release: > > > https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310710=12352870=Text > > > > Staging

[jira] [Created] (SLING-12148) Committer CLI Fails to Parse CI Status

2023-11-13 Thread Dan Klco (Jira)
Dan Klco created SLING-12148: Summary: Committer CLI Fails to Parse CI Status Key: SLING-12148 URL: https://issues.apache.org/jira/browse/SLING-12148 Project: Sling Issue Type: Bug

[jira] [Created] (SLING-12149) ResourceResolver: Illegal mode passthrough for resource provider null

2023-11-13 Thread Joerg Hoh (Jira)
Joerg Hoh created SLING-12149: - Summary: ResourceResolver: Illegal mode passthrough for resource provider null Key: SLING-12149 URL: https://issues.apache.org/jira/browse/SLING-12149 Project: Sling

[jira] [Assigned] (SLING-12149) ResourceResolver: Illegal mode passthrough for resource provider null

2023-11-13 Thread Carsten Ziegeler (Jira)
[ https://issues.apache.org/jira/browse/SLING-12149?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Carsten Ziegeler reassigned SLING-12149: Assignee: Carsten Ziegeler > ResourceResolver: Illegal mode passthrough for

[jira] [Resolved] (SLING-12148) Committer CLI Fails to Parse CI Status

2023-11-13 Thread Dan Klco (Jira)
[ https://issues.apache.org/jira/browse/SLING-12148?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dan Klco resolved SLING-12148. -- Assignee: Dan Klco Resolution: Fixed > Committer CLI Fails to Parse CI Status >

Re: [PR] SLING-12139 - Bump dependency versions [sling-org-apache-sling-testing-hamcrest]

2023-11-13 Thread via GitHub
rombert commented on code in PR #3: URL: https://github.com/apache/sling-org-apache-sling-testing-hamcrest/pull/3#discussion_r1391365542 ## pom.xml: ## @@ -55,7 +55,7 @@ org.apache.sling org.apache.sling.api -2.4.0 +

Re: [PR] SLING-11485 - RepoInitValidator to check for content changes contradi… [sling-org-apache-sling-jcr-repoinit]

2023-11-13 Thread via GitHub
sonarcloud[bot] commented on PR #34: URL: https://github.com/apache/sling-org-apache-sling-jcr-repoinit/pull/34#issuecomment-1808788288 SonarCloud Quality Gate failed. [![Quality Gate

Re: [PR] SLING-12139 - Bump dependency versions [sling-org-apache-sling-testing-hamcrest]

2023-11-13 Thread via GitHub
rmcdouga commented on code in PR #3: URL: https://github.com/apache/sling-org-apache-sling-testing-hamcrest/pull/3#discussion_r1391551624 ## pom.xml: ## @@ -55,7 +55,7 @@ org.apache.sling org.apache.sling.api -2.4.0 +

[jira] [Created] (SLING-12152) IOException is not properly handled by error handling

2023-11-13 Thread Carsten Ziegeler (Jira)
Carsten Ziegeler created SLING-12152: Summary: IOException is not properly handled by error handling Key: SLING-12152 URL: https://issues.apache.org/jira/browse/SLING-12152 Project: Sling

Re: [PR] SLING-12139 - Bump dependency versions [sling-org-apache-sling-testing-hamcrest]

2023-11-13 Thread via GitHub
rmcdouga commented on code in PR #3: URL: https://github.com/apache/sling-org-apache-sling-testing-hamcrest/pull/3#discussion_r1391551624 ## pom.xml: ## @@ -55,7 +55,7 @@ org.apache.sling org.apache.sling.api -2.4.0 +

Re: [PR] SLING-12139 - Bump dependency versions [sling-org-apache-sling-testing-hamcrest]

2023-11-13 Thread via GitHub
rmcdouga commented on code in PR #3: URL: https://github.com/apache/sling-org-apache-sling-testing-hamcrest/pull/3#discussion_r1391551624 ## pom.xml: ## @@ -55,7 +55,7 @@ org.apache.sling org.apache.sling.api -2.4.0 +