Skip to content

build(deps): bump the maven group across 6 directories with 5 updates - #22

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-823cd5265f
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-823cd5265f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven group with 5 updates in the / directory:

Package From To
org.apache.jackrabbit:jackrabbit-jcr-commons 2.20.17 2.22.2
org.jsoup:jsoup 1.22.1 1.23.1
org.apache.shiro:shiro-web 2.1.0 2.2.0
org.springframework.security:spring-security-web 5.8.16 6.5.11
org.apache.tomcat:tomcat-catalina 9.0.117 9.0.118

Bumps the maven group with 2 updates in the /system directory: org.apache.jackrabbit:jackrabbit-jcr-commons and org.jsoup:jsoup.
Bumps the maven group with 2 updates in the /projects/sitemanage directory: org.apache.jackrabbit:jackrabbit-jcr-commons and org.jsoup:jsoup.
Bumps the maven group with 3 updates in the /modules/shindig-uber directory: org.apache.jackrabbit:jackrabbit-jcr-commons, org.jsoup:jsoup and org.apache.shiro:shiro-web.
Bumps the maven group with 1 update in the /modules/segmentation-api directory: org.apache.jackrabbit:jackrabbit-jcr-commons.
Bumps the maven group with 1 update in the /modules/p13n-api directory: org.apache.jackrabbit:jackrabbit-jcr-commons.

Updates org.apache.jackrabbit:jackrabbit-jcr-commons from 2.20.17 to 2.22.2

Changelog

Sourced from org.apache.jackrabbit:jackrabbit-jcr-commons's changelog.

Changes in Jackrabbit 2.22.2

Bug

[JCR-5121] - Java 23: getSubject is supported only if a security manager is allowed

Improvement

[JCR-5146] - Add missing mixin values (defined in JCR 2.0 spec) to JcrConstants
[JCR-5150] - Add missing constant for jcr:title
[JCR-5152] - Add method isValidJcrLocalName(String) to o.a.j.util.Text
[JCR-5161] - NamespaceHelper - get NamespaceRegistry only once

Task

[JCR-5048] - Jackrabbit should build and test with Java 24
[JCR-5089] - avoid use of deprecated junit.framework.Assert
[JCR-5119] - webapp: bump htmlunit to 4.7.0
[JCR-5120] - webapp: update tomcat dependency to 9.0.97
[JCR-5130] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.76.0
[JCR-5132] - webapp: update tomcat dependency to 9.0.104
[JCR-5134] - Update oak-jackrabbit-api.version.used to Oak 1.22.22
[JCR-5135] - Make JNDI support opt-in
[JCR-5143] - Update Mockito dependency to 5.17.0
[JCR-5144] - Update to jacoco version 0.8.13
[JCR-5145] - Upgrade Commons VFS to 2.10.0
[JCR-5147] - remove jackrabbit 1.x compatibility and performance tests
[JCR-5158] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.82.0
[JCR-5159] - Create coverage for NamespaceHelper
[JCR-5177] - jackrabbit-jcr2spi: update to commons-collections4 4.5.0

For more detailed information about all the changes in this and other Jackrabbit releases, please see the Jackrabbit issue tracker at

https://issues.apache.org/jira/browse/JCR

Release Contents

This release consists of a single source archive packaged as a zip file. The archive can be unpacked with the jar tool from your JDK installation. See the README.txt file for instructions on how to build this release.

The source archive is accompanied by an SHA512 checksum and a PGP signature that you can use to verify the authenticity of your download. The public key used for the PGP signature can be found at https://www.apache.org/dist/jackrabbit/KEYS.

... (truncated)

Commits
  • 2b5babf [maven-release-plugin] prepare release jackrabbit-2.22.2
  • 0d7c2e5 JCR-5180: Release Jackrabbit 2.22.2 - Candidate Release Notes (#277)
  • b487b6f JCR-5158: Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.82....
  • 52d8411 JCR-5161: NamespaceHelper - get NamespaceRegistry only once (#259)
  • 6b6171e JCR-5150 Add constant for jcr:title
  • 02b09fd JCR-5159: Create coverage for NamespaceHelper (#256)
  • 0b81850 JCR-5152 Add method to check if a (local) name is valid according to JCR
  • 2e64ea5 JCR-5137: Update JCR commons to implement current jackrabbit-api (#231)
  • 9ba0518 JCR-5089: avoid use of deprecated junit.framework.Assert (#208)
  • 019f6f9 JCR-5177: jackrabbit-jcr2spi: update to commons-collections4 4.5.0 (#270)
  • Additional commits viewable in compare view

Updates org.jsoup:jsoup from 1.22.1 to 1.23.1

Release notes

Sourced from org.jsoup:jsoup's releases.

jsoup 1.23.1

jsoup Java HTML Parser release 1.23.1

jsoup 1.23.1 is out now, with a faster and more memory-efficient HTML parser, improved alignment with the HTML standard across noscript, CDATA, SVG, and MathML parsing, and safer, specification-correct HTTP redirects. The release also adds a fast immutable Element#classList(), direct outer-HTML output to an Appendable, and fixes across RCDATA parsing, XML conversion, tag-name handling, and Cleaner link detection.

Performance optimization was a major focus for this release. In our OpenJDK 21 benchmarks, ordinary string parsing is now 18% faster on average, parsing from an InputStream is 11% faster, and parsing with source position tracking is 70% faster while allocating 64% fewer bytes per document.

Source-tracked DOMs retain 58-65% less memory on representative medium-to-large documents, and the improvements hold under concurrent parsing without introducing new contention. Exact gains will naturally vary with document shape, JVM, and hardware.

This release also fixes a security issue in the Cleaner that could expose markup when malformed HTML is cleaned with a custom Safelist permitting certain raw-text elements. The built-in Safelists are unaffected.

jsoup is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.

Download jsoup now.

Improvements

  • Reduced retained memory when parsing with source position tracking enabled (Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and Position objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping Node#sourceRange(), Element#endSourceRange(), and Attribute#sourceRange() behavior intact. #2498
  • Added Element#classList(), an immutable snapshot of an element's class names in attribute order. Use hasClass() when you just need to test for one class, classList() when you want to read or iterate classes without needing a mutable result, and classNames() when you want the existing mutable, deduplicated set that can be written back with classNames(Set). The class APIs now share an HTML-whitespace scanner, which also makes classNames() faster and lighter on allocation, especially when walking many elements without class names. #2500
  • Aligned HTML parser scope classification with the current HTML spec for select, foreignObject, and template. #2501
  • Simplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. #2502
  • Improved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. #2507
  • <noscript> fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. #2537
  • Improved redirect credential handling as a defense-in-depth measure: explicit authorization headers and request cookies are no longer forwarded across origins, reducing exposure through open redirects and aligning with HTTP guidance. Cookies managed by a CookieStore continue to follow their configured scope. #2540
  • Elements can now append their outer HTML, including their own tags, directly to an Appendable with Node#outerHtml(Appendable), without first creating a String. This complements Element#html(Appendable), which appends inner HTML only. #2532
  • Aligned CDATA tokenization with the HTML spec: CDATA syntax in HTML content is parsed as a bogus comment, while it remains supported in SVG, MathML, and XML. Also improved namespace-aware fragment parsing so SVG and MathML contexts, HTML integration points, and context-sensitive tokenizer states are handled correctly. #2542
  • When using the optional re2j regular expression engine, stack overflows caused by complex selector patterns are now normalized to a ValidationException with a Pattern complexity error message. #2548

Bug Fixes

  • Fixed HTML parsing of mixed-case RCDATA end tags after tag-shaped text. For example, <title><p>Foo</TiTLE> and <textarea><img src=x></TeXtArEa> now keep the tag-shaped content as text instead of promoting it to markup. #2503
  • Fixed W3CDom XML conversion so plain XML elements don't serialize with the reserved XML namespace as the default namespace. Explicit XML namespaces and xml:* attributes are still preserved. #2504
  • Preserve control characters in parsed tag names #2538
  • Updated HTTP redirects to follow the specification: 307 and 308 preserve the request method and content, 301 and 302 only change POST to GET, and Location is followed only for 301, 302, 303, 307, and 308 responses. Streamed request bodies are not buffered; if an automatic redirect requires replaying one, execution fails, so the caller can resend with a fresh stream. #2540
  • Corrected the Cleaner's same-site link detection to compare hostnames rather than URL prefixes when applying rel=nofollow. #2543

Build Changes

  • Cleaned up the Maven build for the multi-release JAR so Java 8 and Java 11+ sources compile as separate source sets. This avoids spurious Java 8 compiler warnings from newer-language overlay sources, keeps long-running parser checks behind an explicit profile, and preserves the same published artifacts and runtime behavior.
  • Improved parallelism and tuned timing in our integration tests, so that a full mvn clean verify drops from ~ 1m18s to ~ 21 seconds.

My sincere thanks to everyone who contributed to this release! If you have any suggestions for the next release, I would love to hear them; please get in touch via jsoup discussions, or with me directly.

You can also follow me (@jhy@tilde.zone) on Mastodon / Fediverse to receive occasional notes about jsoup releases.

jsoup 1.22.2

jsoup 1.22.2 is out now, with fixes and refinements across the library. It makes editing the DOM during traversal more predictable, refreshes the default HTML tag definitions with newer elements and better text boundaries, and improves reliability in parsing and HTTP transport. The release also fixes a number of edge cases in cleaning, stream parsing, XML doctype handling, and Android packaging.

jsoup is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.

... (truncated)

Changelog

Sourced from org.jsoup:jsoup's changelog.

1.23.1 (2026-Jul-30)

Improvements

  • Reduced retained memory when parsing with source position tracking enabled (Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and Position objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping Node#sourceRange(), Element#endSourceRange(), and Attribute#sourceRange() behavior intact. #2498
  • Added Element#classList(), an immutable snapshot of an element's class names in attribute order. Use hasClass() when you just need to test for one class, classList() when you want to read or iterate classes without needing a mutable result, and classNames() when you want the existing mutable, deduplicated set that can be written back with classNames(Set). The class APIs now share an HTML-whitespace scanner, which also makes classNames() faster and lighter on allocation, especially when walking many elements without class names. #2500
  • Aligned HTML parser scope classification with the current HTML spec for select, foreignObject, and template. #2501
  • Simplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. #2502
  • Improved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. #2507
  • <noscript> fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. #2537
  • Improved redirect credential handling as a defense-in-depth measure: explicit authorization headers and request cookies are no longer forwarded across origins, reducing exposure through open redirects and aligning with HTTP guidance. Cookies managed by a CookieStore continue to follow their configured scope. #2540
  • Elements can now append their outer HTML, including their own tags, directly to an Appendable with Node#outerHtml(Appendable), without first creating a String. This complements Element#html(Appendable), which appends inner HTML only. #2532
  • Aligned CDATA tokenization with the HTML spec: CDATA syntax in HTML content is parsed as a bogus comment, while it remains supported in SVG, MathML, and XML. Also improved namespace-aware fragment parsing so SVG and MathML contexts, HTML integration points, and context-sensitive tokenizer states are handled correctly. #2542
  • When using the optional re2j regular expression engine, stack overflows caused by complex selector patterns are now normalized to a ValidationException with a Pattern complexity error message. #2548

Bug Fixes

  • Fixed HTML parsing of mixed-case RCDATA end tags after tag-shaped text. For example, <title><p>Foo</TiTLE> and <textarea><img src=x></TeXtArEa> now keep the tag-shaped content as text instead of promoting it to markup. #2503
  • Fixed W3CDom XML conversion so plain XML elements don't serialize with the reserved XML namespace as the default namespace. Explicit XML namespaces and xml:* attributes are still preserved. #2504
  • Preserve control characters in parsed tag names #2538
  • Updated HTTP redirects to follow the specification: 307 and 308 preserve the request method and content, 301 and 302 only change POST to GET, and Location is followed only for 301, 302, 303, 307, and 308 responses. Streamed request bodies are not buffered; if an automatic redirect requires replaying one, execution fails, so the caller can resend with a fresh stream. #2540
  • Corrected the Cleaner's same-site link detection to compare hostnames rather than URL prefixes when applying rel=nofollow. #2543

Build Changes

  • Cleaned up the Maven build for the multi-release JAR so Java 8 and Java 11+ sources compile as separate source sets. This avoids spurious Java 8 compiler warnings from newer-language overlay sources, keeps long-running parser checks behind an explicit profile, and preserves the same published artifacts and runtime behavior.
  • Improved parallelism and tuned timing in our integration tests, so that a full mvn clean verify drops from ~ 1m18s to ~ 21 seconds.

1.22.2 (2026-Apr-20)

Improvements

  • Expanded and clarified NodeTraversor support for in-place DOM rewrites during NodeVisitor.head(). Current-node edits such as remove, replace, and unwrap now recover more predictably, while traversal stays within the original root subtree. This makes single-pass tree cleanup and normalization visitors easier to write, for example when unwrapping presentational elements or replacing text nodes as you walk the DOM. #2472
  • Documentation: clarified that a configured Cleaner may be reused across concurrent threads, and that shared Safelist instances should not be mutated while in use. #2473
  • Updated the default HTML TagSet for current HTML elements: added dialog, search, picture, and slot; made ins, del, button, audio, video, and canvas inline by default (Tag#isInline(), aligned to phrasing content in the spec); and added readable Element.text() boundaries for controls and embedded objects via the new Tag.TextBoundary option. This improves pretty-printing and keeps normalized text from running adjacent words together. #2493

Bug Fixes

  • Android (R8/ProGuard): added a rule to ignore the optional re2j dependency when not present. #2459
  • Fixed a NodeTraversor regression in 1.21.2 where removing or replacing the current node during head() could revisit the replacement node and loop indefinitely. The traversal docs now also clarify which inserted nodes are visited in the current pass. #2472
  • Parsing during charset sniffing no longer fails if an advisory available() call throws IOException, as seen on JDK 8 HttpURLConnection. #2474
  • Cleaner no longer makes relative URL attributes in the input document absolute when cleaning or validating a Document. URL normalization now applies only to the cleaned output, and Safelist.isSafeAttribute() is side effect free. #2475
  • Cleaner no longer duplicates enforced attributes when the input Document preserves attribute case. A case-variant source attribute is now replaced by the enforced attribute in the cleaned output. #2476
  • If a per-request SOCKS proxy is configured, jsoup now avoids using the JDK HttpClient, because the JDK would silently ignore that proxy and attempt to connect directly. Those requests now fall back to the legacy HttpURLConnection transport instead, which does support SOCKS. #2468
  • Connection.Response.streamParser() and DataUtil.streamParser(Path, ...) could fail on small inputs without a declared charset, if the initial 5 KB charset sniff fully consumed the input and closed it before the stream parse began. #2483
  • In XML mode, doctypes with an internal subset, such as <!DOCTYPE root [<!ENTITY name "value">]>, now round-trip correctly. The subset is preserved as raw text only; entities are not expanded and external DTDs are not loaded. #2486

Build Changes

  • Migrated the integration test server from Jetty to Netty, which actively maintains support for our minimum JDK target (8). #2491
Commits
  • bb077a8 [maven-release-plugin] prepare release jsoup-1.23.1
  • cdb5579 Harden the test some
  • b86b282 Normalize re2j complexity exceptions
  • 0fcc369 Bump github/codeql-action from 4.37.0 to 4.37.1
  • aea4a1b Bump actions/setup-java from 5.5.0 to 5.6.0
  • ec9c879 Bump actions/checkout from 7.0.0 to 7.0.1
  • 1fb2c97 Fix KeyVal.inputStream validation
  • 3475afc Handle non-string internal attribute values; test for internal attribute data
  • be8c375 Parse CDATA according to the context namespace
  • 8996fce Add appendable outer HTML output
  • Additional commits viewable in compare view

Updates org.apache.shiro:shiro-web from 2.1.0 to 2.2.0

Release notes

Sourced from org.apache.shiro:shiro-web's releases.

Apache Shiro 2.2.0

New Contributors

Bug Fixes

Security Enhancements

Improvements

... (truncated)

Commits
  • 8454a31 [maven-release-plugin] prepare release shiro-root-2.2.0
  • 0819229 chore: remove extra newline
  • a46600f improvement: implemented session key rotation via changeSessionId() in Web-Co...
  • be31c13 enh(jakarta-ee): encrypt SAVED_REQUEST_KEY cookie
  • 97218c0 Merge pull request #2689 from apache/dependabot/github_actions/github-actions...
  • d6246a0 Merge pull request #2691 from apache/dependabot/maven/org.apache.karaf.featur...
  • 5ab9e46 Merge pull request #2692 from apache/dependabot/maven/org.owasp-dependency-ch...
  • 4cb75d9 chore(deps): bump org.owasp:dependency-check-maven from 12.2.1 to 12.2.2
  • 05a915f chore(deps): bump org.apache.karaf.features:framework
  • 0cc8c1a chore(deps): bump github/codeql-action
  • Additional commits viewable in compare view

Updates org.springframework.security:spring-security-web from 5.8.16 to 6.5.11

Release notes

Sourced from org.springframework.security:spring-security-web's releases.

6.5.11

🪲 Bug Fixes

  • FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #19136

🔨 Dependency Upgrades

  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #19185
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34 #19299
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.6 to 2.18.7 #19129
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.7 to 2.18.8 #19297
  • Bump gradle-wrapper from 8.14.4 to 8.14.5 #19159
  • Bump org-bouncycastle from 1.80 to 1.80.2 #19204
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #19205
  • Bump org.hibernate.orm:hibernate-core from 6.6.49.Final to 6.6.50.Final #19150
  • Bump org.hibernate.orm:hibernate-core from 6.6.50.Final to 6.6.51.Final #19213
  • Bump org.hibernate.orm:hibernate-core from 6.6.51.Final to 6.6.53.Final #19300
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #19173
  • Bump org.springframework:spring-framework-bom from 6.2.18 to 6.2.19 #19293
  • Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 #19124
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #19183
  • Update micrometer-bom to 1.15.12 #19302
  • Update to Micrometer 1.15.11 #19224
  • Update to reactor-bom 2024.0.18 #19301

🔩 Build Updates

6.5.10

⭐ New Features

  • Add CredentialRecordOwnerAuthorizationManager #19004
  • Add XML Based shouldWriteHeadersEagerly tests #19017
  • Clarify Session Management Persistence Documentation #18345
  • Update FilterChainProxy#getFilters(String) javadoc #18258

🪲 Bug Fixes

  • Add equals and hashcode to HttpMethodRequestMatcher #18914
  • auth_time validation fails when SSO session is renewed #18839
  • Fallback defaultTargetUrl if refererHeader is empty #18806
  • Fix HttpSessionRequestCache#getMatchingRequest query string parsing #16914
  • Fix documentation for Custom Authorization Manager #18362
  • Improve serialVersionUID check in tests #18474
  • Merge Handle null value in OnCommittedResponseWrapper header methods #18989
  • OAuth2 client sessionManagement ineffective with DefaultOidcUser #18622

🔨 Dependency Upgrades

... (truncated)

Commits
  • 73b0777 Release 6.5.11
  • fd5dae5 Sync branch '6.5.x'
  • 700a453 Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34
  • 3a394c6 Update micrometer-bom to 1.15.12
  • 79f9bec Update to reactor-bom 2024.0.18
  • 5b01936 Bump org.hibernate.orm:hibernate-core from 6.6.51.Final to 6.6.53.Final
  • f9b4afd Bump com.fasterxml.jackson:jackson-bom from 2.18.7 to 2.18.8
  • f325ddb Bump org.springframework:spring-framework-bom from 6.2.18 to 6.2.19
  • 4adfdf6 Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16
  • e91b81a Bump org-bouncycastle from 1.80 to 1.80.2
  • Additional commits viewable in compare view

Updates org.apache.tomcat:tomcat-catalina from 9.0.117 to 9.0.118

Updates org.apache.jackrabbit:jackrabbit-jcr-commons from 2.20.17 to 2.22.2

Changelog

Sourced from org.apache.jackrabbit:jackrabbit-jcr-commons's changelog.

Changes in Jackrabbit 2.22.2

Bug

[JCR-5121] - Java 23: getSubject is supported only if a security manager is allowed

Improvement

[JCR-5146] - Add missing mixin values (defined in JCR 2.0 spec) to JcrConstants
[JCR-5150] - Add missing constant for jcr:title
[JCR-5152] - Add method isValidJcrLocalName(String) to o.a.j.util.Text
[JCR-5161] - NamespaceHelper - get NamespaceRegistry only once

Task

[JCR-5048] - Jackrabbit should build and test with Java 24
[JCR-5089] - avoid use of deprecated junit.framework.Assert
[JCR-5119] - webapp: bump htmlunit to 4.7.0
[JCR-5120] - webapp: update tomcat dependency to 9.0.97
[JCR-5130] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.76.0
[JCR-5132] - webapp: update tomcat dependency to 9.0.104
[JCR-5134] - Update oak-jackrabbit-api.version.used to Oak 1.22.22
[JCR-5135] - Make JNDI support opt-in
[JCR-5143] - Update Mockito dependency to 5.17.0
[JCR-5144] - Update to jacoco version 0.8.13
[JCR-5145] - Upgrade Commons VFS to 2.10.0
[JCR-5147] - remove jackrabbit 1.x compatibility and performance tests
[JCR-5158] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.82.0
[JCR-5159] - Create coverage for NamespaceHelper
[JCR-5177] - jackrabbit-jcr2spi: update to commons-collections4 4.5.0

For more detailed information about all the changes in this and other Jackrabbit releases, please see the Jackrabbit issue tracker at

https://issues.apache.org/jira/browse/JCR

Release Contents

This release consists of a single source archive packaged as a zip file. The archive can be unpacked with the jar tool from your JDK installation. See the README.txt file for instructions on how to build this release.

The source archive is accompanied by an SHA512 checksum and a PGP signature that you can use to verify the authenticity of your download. The public key used for the PGP signature can be found at https://www.apache.org/dist/jackrabbit/KEYS.

... (truncated)

Commits
  • 2b5babf [maven-release-plugin] prepare release jackrabbit-2.22.2
  • 0d7c2e5 JCR-5180: Release Jackrabbit 2.22.2 - Candidate Release Notes (#277)
  • b487b6f JCR-5158: Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.82....
  • 52d8411 JCR-5161: NamespaceHelper - get NamespaceRegistry only once (#259)
  • 6b6171e JCR-5150 Add constant for jcr:title
  • 02b09fd JCR-5159: Create coverage for NamespaceHelper (#256)
  • 0b81850 JCR-5152 Add method to check if a (local) name is valid according to JCR
  • 2e64ea5 JCR-5137: Update JCR commons to implement current jackrabbit-api (#231)
  • 9ba0518 JCR-5089: avoid use of deprecated junit.framework.Assert (#208)
  • 019f6f9 JCR-5177: jackrabbit-jcr2spi: update to commons-collections4 4.5.0 (#270)
  • Additional commits viewable in compare view

Updates org.jsoup:jsoup from 1.22.1 to 1.23.1

Release notes

Sourced from org.jsoup:jsoup's releases.

jsoup 1.23.1

jsoup Java HTML Parser release 1.23.1

jsoup 1.23.1 is out now, with a faster and more memory-efficient HTML parser, improved alignment with the HTML standard across noscript, CDATA, SVG, and MathML parsing, and safer, specification-correct HTTP redirects. The release also adds a fast immutable Element#classList(), direct outer-HTML output to an Appendable, and fixes across RCDATA parsing, XML conversion, tag-name handling, and Cleaner link detection.

Performance optimization was a major focus for this release. In our OpenJDK 21 benchmarks, ordinary string parsing is now 18% faster on average, parsing from an InputStream is 11% faster, and parsing with source position tracking is 70% faster while allocating 64% fewer bytes per document.

Source-tracked DOMs retain 58-65% less memory on representative medium-to-large documents, and the improvements hold under concurrent parsing without introducing new contention. Exact gains will naturally vary with document shape, JVM, and hardware.

This release also fixes a security issue in the Cleaner that could expose markup when malformed HTML is cleaned with a custom Safelist permitting certain raw-text elements. The built-in Safelists are unaffected.

jsoup is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.

Download jsoup now.

Improvements

  • Reduced retained memory when parsing with source position tracking enabled (Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and Position objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping Node#sourceRange(), Element#endSourceRange(), and Attribute#sourceRange() behavior intact. #2498
  • Added Element#classList(), an immutable snapshot of an element's class names in attribute order. Use hasClass() when you just need to test for one class, classList() when you want to read or iterate classes without needing a mutable result, and classNames() when you want the existing mutable, deduplicated set that can be written back with classNames(Set). The class APIs now share an HTML-whitespace scanner, which also makes classNames() faster and lighter on allocation, especially when walking many elements without class names. #2500
  • Aligned HTML parser scope classification with the current HTML spec for select, foreignObject, and template. #2501
  • Simplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. #2502
  • Improved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. #2507
  • <noscript> fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. #2537
  • Improved redirect credential handling as a defense-in-depth measure: explicit authorization headers and request cookies are no longer forwarded across origins, reducing exposure through open redirects and aligning with HTTP guidance. Cookies managed by a CookieStore continue to follow their configured scope. #2540
  • Elements can now append their outer HTML, including their own tags, directly to an Appendable with Node#outerHtml(Appendable), without first creating a String. This complements Element#html(Appendable), which appends inner HTML only. #2532
  • Aligned CDATA tokenization with the HTML spec: CDATA syntax in HTML content is parsed as a bogus comment, while it remains supported in SVG, MathML, and XML. Also improved namespace-aware fragment parsing so SVG and MathML contexts, HTML integration points, and context-sensitive tokenizer states are handled correctly. #2542
  • When using the optional re2j regular expression engine, stack overflows caused by complex selector patterns are now normalized to a ValidationException with a Pattern complexity error message. #2548

Bug Fixes

  • Fixed HTML parsing of mixed-case RCDATA end tags after tag-shaped text. For example, <title><p>Foo</TiTLE> and <textarea><img src=x></TeXtArEa> now keep the tag-shaped content as text instead of promoting it to markup. #2503
  • Fixed W3CDom XML conversion so plain XML elements don't serialize with the reserved XML namespace as the default namespace. Explicit XML namespaces and xml:* attributes are still preserved. #2504
  • Preserve control characters in parsed tag names #2538
  • Updated HTTP redirects to follow the specification: 307 and 308 preserve the request method and content, 301 and 302 only change POST to GET, and Location is followed only for 301, 302, 303, 307, and 308 responses. Streamed request bodies are not buffered; if an automatic redirect requires replaying one, execution fails, so the caller can resend with a fresh stream. #2540
  • Corrected the Cleaner's same-site link detection to compare hostnames rather than URL prefixes when applying rel=nofollow. #2543

Build Changes

  • Cleaned up the Maven build for the multi-release JAR so Java 8 and Java 11+ sources compile as separate source sets. This avoids spurious Java 8 compiler warnings from newer-language overlay sources, keeps long-running parser checks behind an explicit profile, and preserves the same published artifacts and runtime behavior.
  • Improved parallelism and tuned timing in our integration tests, so that a full mvn clean verify drops from ~ 1m18s to ~ 21 seconds.

My sincere thanks to everyone who contributed to this release! If you have any suggestions for the next release, I would love to hear them; please get in touch via jsoup discussions, or with me directly.

You can also follow me (@jhy@tilde.zone) on Mastodon / Fediverse to receive occasional notes about jsoup releases.

jsoup 1.22.2

jsoup 1.22.2 is out now, with fixes and refinements across the library. It makes editing the DOM during traversal more predictable, refreshes the default HTML tag definitions with newer elements and better text boundaries, and improves reliability in parsing and HTTP transport. The release also fixes a number of edge cases in cleaning, stream parsing, XML doctype handling, and Android packaging.

jsoup is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.

... (truncated)

Changelog

Sourced from org.jsoup:jsoup's changelog.

1.23.1 (2026-Jul-30)

Improvements

  • Reduced retained memory when parsing with source position tracking enabled (Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and Position objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping Node#sourceRange(), Element#endSourceRange(), and Attribute#sourceRange() behavior intact. #2498
  • Added Element#classList(), an immutable snapshot of an element's class names in attribute order. Use hasClass() when you just need to test for one class, classList() when you want to read or iterate classes without needing a mutable result, and classNames() when you want the existing mutable, deduplicated set that can be written back with classNames(Set). The class APIs now share an HTML-whitespace scanner, which also makes classNames() faster and lighter on allocation, especially when walking many elements without class names. #2500
  • Aligned HTML parser scope classification with the current HTML spec for select, foreignObject, and template. #2501
  • Simplified the HTML tree builder's scope, implied-e...

    Description has been truncated

Bumps the maven group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) | `2.20.17` | `2.22.2` |
| [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.22.1` | `1.23.1` |
| [org.apache.shiro:shiro-web](https://github.com/apache/shiro) | `2.1.0` | `2.2.0` |
| [org.springframework.security:spring-security-web](https://github.com/spring-projects/spring-security) | `5.8.16` | `6.5.11` |
| org.apache.tomcat:tomcat-catalina | `9.0.117` | `9.0.118` |

Bumps the maven group with 2 updates in the /system directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) and [org.jsoup:jsoup](https://github.com/jhy/jsoup).
Bumps the maven group with 2 updates in the /projects/sitemanage directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) and [org.jsoup:jsoup](https://github.com/jhy/jsoup).
Bumps the maven group with 3 updates in the /modules/shindig-uber directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit), [org.jsoup:jsoup](https://github.com/jhy/jsoup) and [org.apache.shiro:shiro-web](https://github.com/apache/shiro).
Bumps the maven group with 1 update in the /modules/segmentation-api directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit).
Bumps the maven group with 1 update in the /modules/p13n-api directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit).


Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2
- [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt)
- [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2)

Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1
- [Release notes](https://github.com/jhy/jsoup/releases)
- [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md)
- [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1)

Updates `org.apache.shiro:shiro-web` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/apache/shiro/releases)
- [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES)
- [Commits](apache/shiro@shiro-root-2.1.0...shiro-root-2.2.0)

Updates `org.springframework.security:spring-security-web` from 5.8.16 to 6.5.11
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@5.8.16...6.5.11)

Updates `org.apache.tomcat:tomcat-catalina` from 9.0.117 to 9.0.118

Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2
- [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt)
- [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2)

Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1
- [Release notes](https://github.com/jhy/jsoup/releases)
- [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md)
- [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1)

Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2
- [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt)
- [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2)

Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1
- [Release notes](https://github.com/jhy/jsoup/releases)
- [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md)
- [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1)

Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2
- [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt)
- [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2)

Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1
- [Release notes](https://github.com/jhy/jsoup/releases)
- [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md)
- [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1)

Updates `org.apache.shiro:shiro-web` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/apache/shiro/releases)
- [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES)
- [Commits](apache/shiro@shiro-root-2.1.0...shiro-root-2.2.0)

Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 1.6.0 to 2.22.2
- [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt)
- [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2)

Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 1.6.0 to 2.22.2
- [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt)
- [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2)

---
updated-dependencies:
- dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons
  dependency-version: 2.22.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.jsoup:jsoup
  dependency-version: 1.23.1
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.shiro:shiro-web
  dependency-version: 2.2.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.springframework.security:spring-security-web
  dependency-version: 6.5.11
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.tomcat:tomcat-catalina
  dependency-version: 9.0.118
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons
  dependency-version: 2.22.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.jsoup:jsoup
  dependency-version: 1.23.1
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons
  dependency-version: 2.22.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.jsoup:jsoup
  dependency-version: 1.23.1
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons
  dependency-version: 2.22.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.jsoup:jsoup
  dependency-version: 1.23.1
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.shiro:shiro-web
  dependency-version: 2.2.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons
  dependency-version: 2.22.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons
  dependency-version: 2.22.2
  dependency-type: direct:production
  dependency-group: maven
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Aug 12, 2026

@natechadwick-intsof natechadwick-intsof left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Java 8 compatibility review

Do not merge as-is. At least three of the five root bumps are incompatible with the Java 8 LTS line.

Incompatible (must not land)

Package From → To Evidence Notes
org.springframework.security:spring-security-web 5.8.16 → 6.5.11 JAR class major 61 = Java 17; Gradle metadata org.gradle.jvm.version: 17 Also pulls spring-*:6.2.19. Spring Security 6 requires Spring Framework 6 + Jakarta. Current 5.8.16 is major 52 (Java 8).
org.apache.jackrabbit:jackrabbit-jcr-commons 2.20.17 → 2.22.2 (and 1.6.0 → 2.22.2 in p13n/segmentation) Class major 55 = Java 11 2.20.17 is still Java 8 (major 52). This is also a large major jump from 1.6.0 in two modules.
org.apache.shiro:shiro-web 2.1.0 → 2.2.0 Class major 55 = Java 11 Note: 2.1.0 is already Java 11 bytecode — already past a pure Java 8 Shiro line. Still should not bump further without an intentional Java 11 plan.

Compatible on their own (but do not save this PR)

Package From → To Evidence
org.jsoup:jsoup 1.22.1 → 1.23.1 Class major 52 (Java 8)
org.apache.tomcat:tomcat-catalina 9.0.117 → 9.0.118 Non-module classes major 52 (Java 8); Tomcat 9 remains the Java 8-capable line

Dependabot policy

.github/dependabot.yml on main already intends to block:

  • org.springframework.security* versions >= 5.9.0
  • org.apache.jackrabbit:jackrabbit-jcr-commons versions >= 2.21.0
  • org.apache.shiro* versions >= 2.0.0

This PR shows those ignores are still not fully preventing grouped multi-directory updates. Recommend:

  1. Close this PR (or drop the three incompatible deps and re-open only jsoup + tomcat if desired).
  2. Tighten Dependabot ignores for Spring Security (and optionally full-ignore Shiro majors) so spring-security-web 6.x cannot reappear in a group PR.
  3. Keep Spring Security on the 5.8.x Java 8 line; security fixes for 6.x are not usable here without a Java 17 + Spring Framework 6 migration.

Recommendation

Request changes / close. The spring.security.version bump alone would break a Java 8 runtime (and fight the rest of the tree still on Spring 5.3.x / javax.*).

@natechadwick-intsof

Copy link
Copy Markdown
Collaborator

Closing: Java 8 incompatible. Review confirmed:

  • spring-security-web 6.5.11 requires Java 17 (bytecode major 61) and pulls Spring Framework 6.2.x
  • jackrabbit-jcr-commons 2.22.2 requires Java 11 (major 55); stay on 2.20.x
  • shiro-web 2.2.0 is Java 11 (as is current 2.1.0)

jsoup 1.23.1 and Tomcat 9.0.118 would be fine alone, but this grouped PR is not mergeable.

Follow-up: tighten Dependabot ignores so these cannot reappear in group PRs.

@dependabot @github

dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant