Skip to content

JCR-5238: Release Jackrabbit 2.22.4 - #364

Closed
reschke wants to merge 177 commits into
2.22from
trunk
Closed

JCR-5238: Release Jackrabbit 2.22.4#364
reschke wants to merge 177 commits into
2.22from
trunk

Conversation

@reschke

@reschke reschke commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

No description provided.

reschke and others added 30 commits June 7, 2024 07:47
Those only matter for maven plugins, all other packagings need to use
maven-enforcer instead for build time prerequisites
…and javax.jcr.nodetype.NodeType - fix broken Javadoc
reschke and others added 29 commits April 1, 2026 12:33
…ts featuring only Slf4j v2 or even Tika v2.9 (#337)

Added tests.
Adds a draft project-level security threat-model document
(draft-THREAT-MODEL.md) at repo root, improving discoverability
for automated security scanners running against this repository.
The file follows the rubric format used by several other ASF
projects piloting security-model discoverability.

The "draft-" prefix signals this is a proposal for the PMC to
review, correct, or reject — not a finalised maintainer-blessed
model. Every claim carries a provenance tag (documented /
inferred / maintainer) so reviewers can see where each claim
originates; §14 collects open questions for the maintainers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…/commons/namespace/SessionNamespaceResolver.java

Co-authored-by: Julian Reschke <reschke@apache.org>
JCR-5249 : added broken prefix to exception message
Per PR review by @reschke: RMI support was removed from the current
codebase (JCR-5042, ~2 years ago) and remains only in the 2.20.x
maintenance branch slated for EOL, so it is out of scope for this
model. Removes the jackrabbit-jcr-rmi module, its trust-boundary /
entry-point / asset rows, finding P8 (RMI deserialisation), section
9.5, and the RMI residual-risk / FAQ / non-goal bullets and two
RMI-specific open questions; renumbers findings, subsections, trust
boundaries, and open questions sequentially with cross-references fixed.
…026-05-30

Add draft project security threat-model document
Adds AGENTS.md (## Security pointer) + SECURITY.md wiring the
conventional AGENTS.md -> SECURITY.md -> THREAT_MODEL.md chain, and
renames the PMC-merged draft-THREAT-MODEL.md to the canonical
THREAT_MODEL.md (no longer a draft; matches the discoverable
convention). No model content changes.

Generated-by: Claude Code (Claude Opus 4.8)
…rability-2026-07-15

Wire the security threat model for agent discoverability (AGENTS.md + SECURITY.md); rename draft-THREAT-MODEL.md -> THREAT_MODEL.md
@reschke reschke closed this Aug 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants