Reviewed 2026-09-25 (America/Los_Angeles) against main at bd249f5. Execution order and cross-issue ownership: #169. Batch 00.
This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.
Current state
esapi/README.md still says the published POM defaults to ESAPI 2.7.0.0 without naming the adapter version. The 1.4.0 POM uses [2.5.1.0,3); #99 fixed the dependency and the signed GitHub 1.4.1 release includes it. Central publication is still pending (#111). The old statement that no tag contains the fix is obsolete.
Acceptance criteria
The broader README rewrite is #128 and need not delay this consumer-facing correction.
Batch 00 implementation — 2026-09-25 (America/Los_Angeles)
#171 merged the documentation and installation guidance as 6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6f at 2026-09-26 05:00:48 UTC. All 20 GitHub checks passed on the PR head. Jim explicitly directed the merge after the normal approving-review gate blocked it; the administrator override was used. Maven 3.9.12 / OpenJDK 17.0.20.1 validated both README XML examples in separate fresh repositories with empty user/global settings: 1.4.0 plus the management pin resolves ESAPI 2.7.0.0 but retains core 1.4.0; verified signed 1.4.1 resolves core/adapter 1.4.1 and ESAPI 2.7.0.0. All five documented artifact installations passed without rebuilding.
The 1.4.0 GitHub release notes now carry the narrowly scoped dated pin/upgrade supplement. Original release text and asset metadata were verified unchanged apart from that supplement. Upstream's latest release and security policy were rechecked and identify ESAPI 2.7.0.0 as current and supported. Central 1.4.1 publication remains pending under #111.
Validation evidence. Closed by the merge of #171. Central publication and the remaining operational checks stay open under #111.
Reviewed 2026-09-25 (America/Los_Angeles) against
mainatbd249f5. Execution order and cross-issue ownership: #169. Batch 00.This scope replaces the dated implementation prescriptions in the original report and earlier comments; linked historical evidence remains useful but must be rechecked before implementation.
Current state
esapi/README.mdstill says the published POM defaults to ESAPI 2.7.0.0 without naming the adapter version. The 1.4.0 POM uses[2.5.1.0,3); #99 fixed the dependency and the signed GitHub 1.4.1 release includes it. Central publication is still pending (#111). The old statement that no tag contains the fix is obsolete.Acceptance criteria
dependencyManagementpin for consumers temporarily remaining on 1.4.0, while clearly stating that pinning ESAPI does not fix Java Encoder's published 1.4.1 security advisories; upgrade the encoder as well.The broader README rewrite is #128 and need not delay this consumer-facing correction.
Batch 00 implementation — 2026-09-25 (America/Los_Angeles)
#171 merged the documentation and installation guidance as
6a3c3a9bd5d8eaa82c6ee956ab78ff9e11821b6fat 2026-09-26 05:00:48 UTC. All 20 GitHub checks passed on the PR head. Jim explicitly directed the merge after the normal approving-review gate blocked it; the administrator override was used. Maven 3.9.12 / OpenJDK 17.0.20.1 validated both README XML examples in separate fresh repositories with empty user/global settings: 1.4.0 plus the management pin resolves ESAPI 2.7.0.0 but retains core 1.4.0; verified signed 1.4.1 resolves core/adapter 1.4.1 and ESAPI 2.7.0.0. All five documented artifact installations passed without rebuilding.The 1.4.0 GitHub release notes now carry the narrowly scoped dated pin/upgrade supplement. Original release text and asset metadata were verified unchanged apart from that supplement. Upstream's latest release and security policy were rechecked and identify ESAPI 2.7.0.0 as current and supported. Central 1.4.1 publication remains pending under #111.
Validation evidence. Closed by the merge of #171. Central publication and the remaining operational checks stay open under #111.