·
4 commits
to master
since this release
What's Changed
- Bump org.apache.maven.plugins:maven-release-plugin from 3.1.1 to 3.2.0 by @dependabot[bot] in #73
- Bump actions/checkout from 5 to 6 by @dependabot[bot] in #74
- Bump org.apache.maven.plugins:maven-assembly-plugin from 3.7.1 to 3.8.0 by @dependabot[bot] in #75
- Bump actions/cache from 4 to 5 by @dependabot[bot] in #78
- Bump org.apache.maven.plugins:maven-release-plugin from 3.2.0 to 3.3.1 by @dependabot[bot] in #77
- Bump org.apache:apache from 35 to 36 by @dependabot[bot] in #79
- Bump org.apache:apache from 36 to 37 by @dependabot[bot] in #80
- Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.4 to 3.5.5 by @dependabot[bot] in #81
- Bump com.google.guava:guava-testlib from 33.5.0-jre to 33.6.0-jre by @dependabot[bot] in #84
- Bump github/codeql-action from 4 to 4.35.2 by @dependabot[bot] in #85
- Bump github/codeql-action from 4.35.2 to 4.35.3 by @dependabot[bot] in #86
- Bump github/codeql-action from 4.35.3 to 4.35.4 by @dependabot[bot] in #88
- Bump org.apache:apache from 37 to 38 by @dependabot[bot] in #87
- [INFRA] Set up default rulesets for default and release branches by @asf-gitbox-commits in #89
- Bump slf4j.version from 2.0.17 to 2.0.18 by @dependabot[bot] in #90
- Bump github/codeql-action from 4.35.4 to 4.35.5 by @dependabot[bot] in #91
- Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.6.2 to 3.6.3 by @dependabot[bot] in #92
- Bump org.apache.maven.plugins:maven-site-plugin from 3.21.0 to 3.22.0 by @dependabot[bot] in #93
- Bump actions/cache from 5 to 6 by @dependabot[bot] in #106
- Bump org.apache:apache from 38 to 39 by @dependabot[bot] in #107
- Bump actions/checkout from 6 to 7 by @dependabot[bot] in #102
- Bump actions/setup-java from 5 to 5.4.0 by @dependabot[bot] in #109
- Bump github/codeql-action from 4.35.5 to 4.36.3 by @dependabot[bot] in #108
- Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.5 to 3.5.6 by @dependabot[bot] in #96
- Add draft project security threat-model document by @potiuk in #95
- Reviewed threat model, removed draft by @coheigea in #110
- Wire the security threat model for agent discoverability (AGENTS.md + SECURITY.md) by @potiuk in #113
- Bump actions/setup-java from 5.4.0 to 5.6.0 by @dependabot[bot] in #114
- Bump github/codeql-action from 4.36.3 to 4.37.0 by @dependabot[bot] in #111
- Bump github/codeql-action from 4.37.0 to 4.37.1 by @dependabot[bot] in #115
- Bump github/codeql-action from 4.37.1 to 4.37.3 by @dependabot[bot] in #116
- Bump actions/setup-java from 5.6.0 to 5.7.0 by @dependabot[bot] in #118
- Bump github/codeql-action from 4.37.3 to 4.37.4 by @dependabot[bot] in #117
- Bump github/codeql-action/init from 4.37.4 to 4.37.6 by @dependabot[bot] in #119
- Bump github/codeql-action/analyze from 4.37.4 to 4.37.6 by @dependabot[bot] in #120
- Explicitly catch NumberFormatException in XmlSchemaElementValidator by @coheigea in #123
- Use an explicit heap stack in SaxWalkerOverDom by @coheigea in #124
- Add maxDecisionPoints and maxReplayedEvents to the path walker by @coheigea in #125
- Fix state machine generation for shared schema types by @coheigea in #126
- Improve cycle detection in the schema walker by @coheigea in #127
- Fix resolved schema cache key collisions and validate cache hits by @coheigea in #129
- Impose an import depth limit by @coheigea in #130
- Bump com.google.guava:guava-testlib from 33.6.0-jre to 33.7.1-jre by @dependabot[bot] in #128
- Bump github/codeql-action/init from 4.37.6 to 4.37.7 by @dependabot[bot] in #122
- Bump github/codeql-action/analyze from 4.37.6 to 4.37.7 by @dependabot[bot] in #121
- Add max nesting depth by @coheigea in #131
- Properly throw XMLSchemaException in some places by @coheigea in #132
- Bump github/codeql-action/analyze from 4.37.7 to 4.37.8 by @dependabot[bot] in #134
- Bump github/codeql-action/init from 4.37.7 to 4.37.8 by @dependabot[bot] in #133
- Harden default resolver by @coheigea in #135
- Tighten Max/Min Occurs parsing by @coheigea in #136
- Harden internal parser against DTDs by @coheigea in #137
- Fix DOMSource correctness bug by @coheigea in #138
- Bump actions/setup-java from 5.7.0 to 6.0.0 by @dependabot[bot] in #139
- Bump github/codeql-action/analyze from 4.37.8 to 4.37.9 by @dependabot[bot] in #140
- Bump github/codeql-action/init from 4.37.8 to 4.37.9 by @dependabot[bot] in #141
- Group codeql updates by @coheigea in #142
- Bump slf4j.version from 2.0.18 to 2.0.19 by @dependabot[bot] in #144
- Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0 by @dependabot[bot] in #143
- Bump actions/setup-java from 6.0.0 to 6.0.1 by @dependabot[bot] in #146
- Bump the codeql-action group with 2 updates by @dependabot[bot] in #145
- Fix up DTD handling by @coheigea in #147
- Restrict default protocols allowed by the DefaultURIResolver by @coheigea in #148
- Updating docs for remote URI dereferencing by @coheigea in #149
- Exclude a few other things by default in DefaultURIResolver by @coheigea in #150
- Fix some potential NPEs by @coheigea in #151
- Place default limits on read timeouts + size on remote schemas by @coheigea in #152
- Fix scchema resolution budget bug by @coheigea in #153
- Keep document-walk failures distinguishable by @coheigea in #154
- Report unresolvable and complex-where-simple type references as XmlSc… by @coheigea in #155
- Serialize notation as well and fix some NPEs by @coheigea in #156
- Stop capturing foreign children of the document element by @coheigea in #157
- Add a switch to allow network resolution to be turned off by @coheigea in #158
- Add a new property to disable reading local files by @coheigea in #159
- Bump the codeql-action group with 2 updates by @dependabot[bot] in #161
- Bump org.apache:apache from 39 to 40 by @dependabot[bot] in #160
- inherit the substitution group head's type for untyped elements by @coheigea in #162
- Walker: bound the depth of an acyclic schema walk by @coheigea in #163
- Add a bound on the number of redirects the DefaultURIResolver can do by @coheigea in #164
- Adding new org.apache.ws.commons.schema.remote.checkAddresses property by @coheigea in #165
- Make sure file references are to actual files by @coheigea in #166
- Bound the nesting depth of annotation markup by @coheigea in #167
- Check that a relative schema location is a regular file by @coheigea in #168
- Collect ancestor prefix declarations without recursion by @coheigea in #169
- Misc fixes by @coheigea in #170
- Allow an xs:all alongside an empty particle in a complex content exte… by @coheigea in #171
- Fix the path finder refusing or failing on common valid documents by @coheigea in #172
- Do not declare an empty prefix for an unhandled attribute value by @coheigea in #173
- Keep complexType block, union members and keyref refer through read a… by @coheigea in #174
- Check the file the parser opens for a relative schema location by @coheigea in #175
- Read "1" and surrounding whitespace as true for xs:boolean attributes by @coheigea in #176
- Do not build a wire name for an element or attribute with no name by @coheigea in #177
- Count a cached base type's whole derivation chain against the walk depth by @coheigea in #178
- Bound the element depth of the schema parse by @coheigea in #179
- Misc fixes by @coheigea in #180
- Refuse an element declaration with no name and no ref in the walker by @coheigea in #181
- The walker changes the schema model by @coheigea in #182
- Limit entity expansion by @coheigea in #183
- Check a file: location relative to the working directory as a regular… by @coheigea in #184
- Close the connection when a remote fetch is refused before its body by @coheigea in #185
- Fix test on JDK8 by @coheigea in #186
New Contributors
- @asf-gitbox-commits made their first contribution in #89
- @potiuk made their first contribution in #95
Full Changelog: xmlschema-2.3.2...xmlschema-2.3.3