The GitHub Actions job "Java CI" on commons-text.git/feat/use-commons-xml has 
succeeded.
Run started by GitHub user ppkarwasz (triggered by ppkarwasz).

Head commit for run:
f758b18bc4e8c0203eb501618d803c46cb04d81a / Piotr P. Karwasz 
<[email protected]>
Harden XML parsing via commons-secure-xml

Create XmlStringLookup's document builder and XPath factories through
org.apache.commons:commons-secure-xml. The secure factories enable
FEATURE_SECURE_PROCESSING and install a non-removable entity-resolver
floor on every parser they produce: external DTD and entity lookups are
resolved to empty content instead of being fetched, and internal entity
expansion is bounded, regardless of the JAXP implementation on the
classpath.

Changes:
- Add the commons-secure-xml dependency (1.0.0-SNAPSHOT until its first
  release).
- Route factory creation through SecureDocumentBuilderFactory and
  SecureXPathFactory in XmlStringLookup when the instance's feature map
  enables secure processing. The documented opt-outs keep their
  meaning: feature maps without secure processing, and the standard
  javax.xml.accessExternalDTD system property (which the secure
  factory's resolver floor would otherwise ignore), keep using the
  plain JAXP factories, so external entity resolution can be restored
  where it is wanted.
- Adapt the secure-path tests to the secure contract: a parser may
  either reject a document with an external reference or parse it with
  the reference resolved to empty content; the tests now assert that
  the external content does not leak into the result instead of
  expecting one fixed failure mode.
- Run the CI and CodeQL builds with -Puse-apache-snapshots (inherited
  from the org.apache:apache parent POM) so the commons-secure-xml
  SNAPSHOT resolves; CodeQL's autobuild receives the profile through
  MAVEN_ARGS.

Assisted-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01MHgnMnGWHQoH2zD2jFdoMT

Report URL: https://github.com/apache/commons-text/actions/runs/33407514559

With regards,
GitHub Actions via GitBox

Reply via email to