snoopdave commented on PR #201: URL: https://github.com/apache/roller/pull/201#issuecomment-5973463400
🐞Claude Issue: **PR-Review: General Issues** The following issues were found but cannot be attached to a specific line in the diff: - **Blocking:** `CHANGES.md` on `roller-6.1.x` is not updated. Add a 6.1.7 entry: XML parsing now uses Apache Commons Secure XML 1.0.0 (new bundled dependency), and Roller now fails at startup instead of logging an error when the XML-RPC parser cannot be configured. Operators should know about that behaviour change. - **Important:** No CI runs on this PR, because the `roller-6.1.x` workflows trigger only for `master`. I ran `SecureXmlParsersTest` (5) and `SafeSAXBuilderTest` (4) locally on JDK 11: all pass. I also confirmed that `commons-secure-xml` 1.0.0 is on Maven Central with a Java 8 target, and that no other `*Factory.newInstance()` parser construction remains in `app/src/main/java`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
