snoopdave commented on PR #201:
URL: https://github.com/apache/roller/pull/201#issuecomment-5973463400

   🐞Claude Issue: **PR-Review: General Issues**
   
   The following issues were found but cannot be attached to a specific line in 
the diff:
   
   - **Blocking:** `CHANGES.md` on `roller-6.1.x` is not updated. Add a 6.1.7 
entry: XML parsing now uses Apache Commons Secure XML 1.0.0 (new bundled 
dependency), and Roller now fails at startup instead of logging an error when 
the XML-RPC parser cannot be configured. Operators should know about that 
behaviour change.
   - **Important:** No CI runs on this PR, because the `roller-6.1.x` workflows 
trigger only for `master`. I ran `SecureXmlParsersTest` (5) and 
`SafeSAXBuilderTest` (4) locally on JDK 11: all pass. I also confirmed that 
`commons-secure-xml` 1.0.0 is on Maven Central with a Java 8 target, and that 
no other `*Factory.newInstance()` parser construction remains in 
`app/src/main/java`.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to