OWASP Java Encoder 1.4.1 will be the final release of the encoder-esapi adapter. Starting with Java Encoder 1.5.0, we will publish the core, JSP, and Jakarta artifacts without a separate ESAPI integration module.
This will allow Java Encoder and ESAPI to evolve independently, without requiring Java Encoder to carry ESAPI’s dependency graph.
ESAPI can still depend on and call the core Java Encoder APIs. We would be happy to collaborate on a cleaner integration maintained within ESAPI, or on a small, stable change to Java Encoder that would make such an integration easier.
If there are changes we could make without introducing ESAPI or its legacy transitive dependencies into the Java Encoder project, we are all ears.
https://github.com/OWASP/owasp-java-encoder/
OWASP Java Encoder 1.4.1 will be the final release of the encoder-esapi adapter. Starting with Java Encoder 1.5.0, we will publish the core, JSP, and Jakarta artifacts without a separate ESAPI integration module.
This will allow Java Encoder and ESAPI to evolve independently, without requiring Java Encoder to carry ESAPI’s dependency graph.
ESAPI can still depend on and call the core Java Encoder APIs. We would be happy to collaborate on a cleaner integration maintained within ESAPI, or on a small, stable change to Java Encoder that would make such an integration easier.
If there are changes we could make without introducing ESAPI or its legacy transitive dependencies into the Java Encoder project, we are all ears.
https://github.com/OWASP/owasp-java-encoder/