
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements.  See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License.  You may obtain a copy of the License at

https://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

Apache Commons Secure XML 1.1.0 Release Notes
---------------------------------------------

The Apache Commons Secure XML team is pleased to announce the release of Apache Commons Secure XML 1.1.0.

Apache Commons Secure XML provides secure-by-default JAXP factory creation, abstracting over
implementation-specific XXE securing differences between the stock JDK and external JAXP implementations
(Android, Apache Xalan, Apache Xerces, Woodstox, Saxon-HE).

Second release. Requires Java 8 or later.


New features
------------

* COMMONSXML-18:   Add helpers that return a secure, namespace-aware DocumentBuilder, SAXParser or XMLReader directly, without the factory. Thanks to Piotr P. Karwasz, Gary Gregory.

Fixed Bugs
----------

*                  Fix the OpenRewrite migration recipe to target static method calls instead of class references. Thanks to Gary Gregory.
*                  Fix the OpenRewrite migration recipe to add a dependency on org.apache.commons:commons-secure-xml:1.0.0. Thanks to Gary Gregory.
*                  Fix rejection behavior of foreign Templates in SAXTransformerFactory.newTransformerHandler. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Fix a NullPointerException when an XMLFilter with a self-driven parent reader is parsed with a null InputSource. #86 Thanks to Piotr P. Karwasz, Gary Gregory.
* COMMONSXML-17:   Keep a URIResolver already set on a Transformer when it is wrapped, instead of replacing it with the resolver floor. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Create the Transformer of an XMLFilter eagerly and reuse it for every parse. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Report a stylesheet that produces no XMLFilter as a TransformerConfigurationException instead of returning null. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  General Javadoc and site documentation improvements. Thanks to Gary Gregory.

Changes
-------

*                  Bump org.apache.commons:commons-parent from 104 to 105. Thanks to Gary Gregory.
*                  Bump com.android.library from 8.6.1 to 9.4.0 in /android-tests. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Bump commons.graalvm.buildtools.version from 1.1.12 to 1.1.14 (#102). Thanks to Gary Gregory, Dependabot.
*                  Bump androidx.test:runner from 1.5.2 to 1.7.0 in /android-tests (#106). Thanks to Gary Gregory, Dependabot.
*                  Bump com.android.library from 9.4.0 to 9.4.1 in /android-tests (#107). Thanks to Gary Gregory, Dependabot.
*                  Bump gradle-wrapper from 9.7.1 to 9.8.0 in /android-tests (#108). Thanks to Gary Gregory, Dependabot.
*                  Bump org.junit.jupiter:junit-jupiter-api from 5.10.2 to 5.14.4 on Android (#111). Thanks to Gary Gregory, Dependabot.


Historical list of changes: https://commons.apache.org/proper/commons-secure-xml//changes.html

For complete information on Apache Commons Secure XML, including instructions on how to submit bug reports,
patches, or suggestions for improvement, see the Apache Commons Secure XML website:

https://commons.apache.org/proper/commons-secure-xml/

Download page: https://commons.apache.org/proper/commons-secure-xml//download_secure-xml.cgi

Have fun!
-Apache Commons Team

-----------------------------------------------------------------------------

Apache Commons Secure XML 1.0.0 Release Notes
---------------------------------------------

The Apache Commons Secure XML team is pleased to announce the release of Apache Commons Secure XML 1.0.0.

Apache Commons Secure XML provides secure-by-default JAXP factory creation, abstracting over
implementation-specific XXE securing differences between the stock JDK and external JAXP implementations
(Android, Apache Xalan, Apache Xerces, Woodstox, Saxon-HE).

First release. Requires Java 8 or later.


New features
------------

*                  This is the first release of Apache Commons Secure XML. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Add secure-by-default JAXP factory creation via org.apache.commons.xml.secure, donated from the copernik-xml-factory project (https://github.com/copernik-eu/copernik-xml-factory) and covering the stock JDK, Android, Apache Xalan, Apache Xerces, Woodstox, and Saxon-HE. Thanks to Piotr P. Karwasz, Gary Gregory.
* COMMONSXML-9:    Install a non-removable resolver floor on every resolver channel (EntityResolver, LSResourceResolver, URIResolver, and XMLResolver), routing caller-supplied resolvers through it as allow-lists. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Secure the SAXTransformerFactory extension surface (TransformerHandler, TemplatesHandler, and XMLFilter) and TransformerFactory.getAssociatedStylesheet. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Document the threat model on the project site, including the denied-fetch contract and the supported runtime floor (OpenJDK 8 and Android API 33 or later). Thanks to Piotr P. Karwasz, Jarek Potiuk, Gary Gregory.
* COMMONSXML-11:   Add GitHub CI builds for Java 26 and 27-EA. Thanks to Gary Gregory, Piotr P. Karwasz.
*                  Mirror on each factory class every JAXP static factory method, including the Java 9 newDefaultInstance and Java 13 newNSInstance families, all usable on Java 8. Thanks to Piotr P. Karwasz, Gary Gregory.

Fixed Bugs
----------

* COMMONSXML-10:   Block XInclude (xi:include) href resolution by default, since the JAXP external-access properties do not govern it. Thanks to Ta Duc Thien, Piotr P. Karwasz, Gary Gregory.
*                  Honor jdk.xml.overrideDefaultParser on TrAX, XPath and schema factories that recognize it. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Restore the secure configuration when reset() is called on a factory or parser instead of reverting to the implementation defaults. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Parse a Source opted in by a caller-supplied URIResolver using a secure parser. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Secure the document parse behind the InputSource-taking XPath evaluation entry points. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Fall back to the standard factory lookup in the DOM, SAX and schema newDefaultInstance methods on Android. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Delegate the XPathFactory setProperty and getProperty methods introduced in Java 18, so the implementation's properties stay reachable on a secure factory. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Bound the content model a schema expands into, so a compact schema with a large maxOccurs cannot exhaust memory or CPU during validation. Thanks to Piotr P. Karwasz, Gary Gregory.

Changes
-------

* COMMONSXML-1,COMMONSXML-5,COMMONSXML-6,COMMONSXML-7,COMMONSXML-8: Recognize XML implementations by the JAXP features and properties they support instead of by their implementation class name, extending the securing to any compliant implementation. Thanks to Piotr P. Karwasz, Gary Gregory.
* COMMONSXML-4:    Define a consistent contract for denied external fetches: unresolved external references resolve to empty content on every implementation, unless the org.apache.commons.xml.secure.throwOnUnresolved system property requests rejection. Thanks to Piotr P. Karwasz, Gary Gregory.
* COMMONSXML-3:    Reduce the shaded footprint by splitting the secure classes and resolver floors into independent entry points. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Allow the JAXP 1.5 accessExternal properties to be modified on secured factories. Thanks to Piotr P. Karwasz, Gary Gregory.
*                  Clean up the code and documentation after a review. Thanks to Elliotte Rusty Harold, Piotr P. Karwasz.

Removed
-------

* COMMONSXML-2:    Remove the Limits class that applied uniform processing limits across implementations. Thanks to Piotr P. Karwasz, Gary Gregory.

Historical list of changes: https://commons.apache.org/proper/commons-secure-xml//changes.html

For complete information on Apache Commons Secure XML, including instructions on how to submit bug reports,
patches, or suggestions for improvement, see the Apache Commons Secure XML website:

https://commons.apache.org/proper/commons-secure-xml/

Download page: https://commons.apache.org/proper/commons-secure-xml/download_secure-xml.cgi

Have fun!
-Apache Commons Team

-----------------------------------------------------------------------------
