Skip to content

Bump com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20220608.1 to 20260313.1#174

Open
kunalmemane wants to merge 1 commit into
jenkinsci:masterfrom
kunalmemane:owasp-20260102.1
Open

Bump com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20220608.1 to 20260313.1#174
kunalmemane wants to merge 1 commit into
jenkinsci:masterfrom
kunalmemane:owasp-20260102.1

Conversation

@kunalmemane
Copy link
Copy Markdown

@kunalmemane kunalmemane commented Mar 11, 2026

Summary

Details

Upstream release - https://github.com/OWASP/java-html-sanitizer/releases/tag/release-20260313.1

Testing done

Submitter checklist

  • Make sure you are opening from a topic/feature/bugfix branch (right side) and not your main branch!
  • Ensure that the pull request title represents the desired changelog entry
  • Please describe what you did
  • Link to relevant issues in GitHub or Jira
  • Link to relevant pull requests, esp. upstream and downstream changes
  • Ensure you have provided tests that demonstrate the feature works or the issue is fixed

@kunalmemane kunalmemane requested a review from a team as a code owner March 11, 2026 07:12
@kunalmemane kunalmemane force-pushed the owasp-20260102.1 branch 2 times, most recently from 56ce836 to bc35c98 Compare March 11, 2026 10:22
@kunalmemane
Copy link
Copy Markdown
Author

kunalmemane commented Mar 11, 2026

Hi @jglick, Could you please help to review this PR.
Thanks!

@kunalmemane kunalmemane force-pushed the owasp-20260102.1 branch 2 times, most recently from 8244a75 to 0178a84 Compare March 12, 2026 06:59
@jglick
Copy link
Copy Markdown
Member

jglick commented Mar 12, 2026

#121 (comment)

I am not a maintainer.

@kunalmemane
Copy link
Copy Markdown
Author

kunalmemane commented Mar 13, 2026

@christ66 Hi, Kindly request a review on this PR which addresses CVE-2025-66021

@kunalmemane kunalmemane force-pushed the owasp-20260102.1 branch 2 times, most recently from 77f981a to 34e4445 Compare March 13, 2026 17:38
@kunalmemane kunalmemane changed the title Bump com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20220608.1 to 20260102.1 Bump com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer from 20220608.1 to 20260313.1 Mar 13, 2026
@jglick jglick requested a review from daniel-beck March 13, 2026 17:51
@daniel-beck
Copy link
Copy Markdown
Member

🤷 seems OK.

@jglick

I am not a maintainer.

In that case, please remove yourself from https://github.com/jenkins-infra/repository-permissions-updater/blob/2286e628d1aa161208d69a8940f33abeed0acbc9/permissions/plugin-antisamy-markup-formatter.yml#L9, because that's the SSOT for maintainer status.

@kunalmemane
Copy link
Copy Markdown
Author

@daniel-beck If everything seems ok, Can we get it merged?

@daniel-beck
Copy link
Copy Markdown
Member

@kunalmemane I don't see why not, but note that I am not a maintainer. Maintainers are the ones whose Jenkins community user names are listed in the linked YAML file (which may or may not be the same as their GitHub user).

@kunalmemane
Copy link
Copy Markdown
Author

Thank you @daniel-beck, Will reach out to respective maintainers.

@kunalmemane
Copy link
Copy Markdown
Author

Hi @batmat, Kindly request a review on this PR. TY!

@strangelookingnerd
Copy link
Copy Markdown
Contributor

strangelookingnerd commented Mar 20, 2026

@daniel-beck
Copy link
Copy Markdown
Member

daniel-beck commented Mar 21, 2026

Included in this release is also OWASP/java-html-sanitizer#336 which makes my workaround in #134 -> https://github.com/jenkinsci/antisamy-markup-formatter-plugin/pull/134/changes#diff-cacea0dcf3843d82bd010c245ddb10eb502059816818016b456103db0bb06300R120-R127 obsolete.

Nice!

I would not consider that a release blocker though, that can be cleaned up at any time. Nvm, I thought that got integrated, but apparently not. So yeah, JUnit 5 can be adopted later, without needing the workaround for value ordering.

@kunalmemane
Copy link
Copy Markdown
Author

Hi @batmat, just checking back in on this. I've addressed all required changes and PR is ready for review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants