)]}'
{
  "log": [
    {
      "commit": "3a92729981295c115d83e37582f4a5273cf35fca",
      "tree": "6e8be35de91d8062f29e596e812c3e8b2a81e20c",
      "parents": [
        "0afb20de1acc04b39f335ad3dc85e216fe718c6e"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Oct 03 15:02:40 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Oct 03 15:02:40 2026 -0400"
      },
      "message": "Update GH CI from Java 26 to 27\n"
    },
    {
      "commit": "0afb20de1acc04b39f335ad3dc85e216fe718c6e",
      "tree": "4b9f3300475e01d561a3648268e3ec1ded254a90",
      "parents": [
        "c9e587a43843779ecee2151077fcdd62797f7e74"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Sep 29 19:49:56 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Sep 29 19:49:56 2026 +0000"
      },
      "message": "[test] Bump org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0\n"
    },
    {
      "commit": "c9e587a43843779ecee2151077fcdd62797f7e74",
      "tree": "443df1c31b5fbe4ea15e07c1f762b7b8749fcf95",
      "parents": [
        "063b86f50ef0c0d4e26cc58c1c32c10d084f09ec",
        "e614dda14547102a22b01bc1593e0ed4d69b7fa4"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@users.noreply.github.com",
        "time": "Tue Sep 29 15:49:14 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 29 15:49:14 2026 -0400"
      },
      "message": "Merge pull request #417 from garydgregory/fix/commons-lang3-3.21.0\n\nBump org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0"
    },
    {
      "commit": "e614dda14547102a22b01bc1593e0ed4d69b7fa4",
      "tree": "f8bff7d8584c33dc78ab89ab9ec3720f1cc42ff4",
      "parents": [
        "bd6c29732b188bb2fa3a9fc0f80d1a31cfa48cb4"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Sep 29 12:10:43 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Sep 29 12:10:43 2026 -0400"
      },
      "message": "Bump org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0\n"
    },
    {
      "commit": "063b86f50ef0c0d4e26cc58c1c32c10d084f09ec",
      "tree": "1c8ce24775b2b76edaff7032f3015a824de88ae8",
      "parents": [
        "9098d9aab6556b146630c087ce04ea1df9ffcfe5"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Sep 24 12:57:40 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Sep 24 12:57:40 2026 -0400"
      },
      "message": "Bump github/codeql-action from 4.38.1 to 4.38.2\n"
    },
    {
      "commit": "9098d9aab6556b146630c087ce04ea1df9ffcfe5",
      "tree": "8fe9eb3d29af5c60d1d04c95f1fe8cc6b4dca7b1",
      "parents": [
        "bd6c29732b188bb2fa3a9fc0f80d1a31cfa48cb4"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Sep 22 07:26:55 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Sep 22 07:26:55 2026 -0400"
      },
      "message": "Protect main branches\n"
    },
    {
      "commit": "bd6c29732b188bb2fa3a9fc0f80d1a31cfa48cb4",
      "tree": "1dcc5d313e14e150c6e102dba21066c7dd93a75f",
      "parents": [
        "1710d4742cdd2f49f057463c2a95a242154078d0"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Sep 19 11:16:10 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Sep 19 11:16:10 2026 -0400"
      },
      "message": "Bump github/codeql-action/* from 4.37.9 to 4.38.1\n"
    },
    {
      "commit": "1710d4742cdd2f49f057463c2a95a242154078d0",
      "tree": "a926455d57719da1e28c8195ad24df5f4ae5207c",
      "parents": [
        "07ca868bf933b2712d98f534cbb011e43d7d7a58"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Sep 19 11:07:47 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Sep 19 11:07:47 2026 -0400"
      },
      "message": "Bump actions/setup-java from 6.0.0 to 6.0.1\n"
    },
    {
      "commit": "07ca868bf933b2712d98f534cbb011e43d7d7a58",
      "tree": "61d7535233b4fce5b827e3072e92b90fdfbbbf0a",
      "parents": [
        "14fce3a65e743d3395cf439f8006b1940da71ad3",
        "b45ab23936a56ca66d5c38ae1bed1594bf1a5e84"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Mon Sep 14 17:30:20 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 14 17:30:20 2026 +0200"
      },
      "message": "Merge pull request #416 from apache/JEXL-472\n\nJEXL-472 : Add property access for Java record component accessors"
    },
    {
      "commit": "b45ab23936a56ca66d5c38ae1bed1594bf1a5e84",
      "tree": "61d7535233b4fce5b827e3072e92b90fdfbbbf0a",
      "parents": [
        "bdeb80c2d20bd0435320b9652f4332f60a75cc4d"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 17:16:29 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 17:16:29 2026 +0200"
      },
      "message": "JEXL-472: ClassCreatorTest fails on java 28 (GC does not reclaim classes?), fix by avoidance;\n"
    },
    {
      "commit": "bdeb80c2d20bd0435320b9652f4332f60a75cc4d",
      "tree": "550034e75d680891a0ffb62370b863f316837880",
      "parents": [
        "823d4e7ce942c847752c0736b1df910b61f5c825"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 16:28:35 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 16:28:35 2026 +0200"
      },
      "message": "JEXL-472: fix review comments;\n"
    },
    {
      "commit": "823d4e7ce942c847752c0736b1df910b61f5c825",
      "tree": "efd0eeefbc40d1e9ec02f7dfe2ca4d859351a561",
      "parents": [
        "390d204331f86b5515b868a77198ef73dc345a42"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 16:10:54 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 16:10:54 2026 +0200"
      },
      "message": "JEXL-472: fix review comments;\n"
    },
    {
      "commit": "390d204331f86b5515b868a77198ef73dc345a42",
      "tree": "e04eef0bb32e0c415dc693ce420d57472cf04371",
      "parents": [
        "ded79221a3a9dfb4090c22aae3c8ea68cc621d92"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 14:47:43 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 15:43:47 2026 +0200"
      },
      "message": "JEXL-472: Consolidate record reflection into ClassTool, fix test fixture\n\n- Builds on the record accessor support originally proposed by\nAurelien Mino in #415.\n\n- Move the Class#isRecord()/getRecordComponents() reflection out of\nRecordGetExecutor and into the existing ClassTool backport utility,\nresolved via MethodHandle to match how it already backports Java 9+\nmodule reflection, instead of duplicating a separate Method-based\nlookup.\n\n- Fix RecordPropertyAccessTest\u0027s on-the-fly compiled record fixture to\nactually compile into org.apache.commons.jexl3. Also switch the test to extend JexlTestCase and use the shared restricted-permissions engine instead of a bespoke\nUNRESTRICTED-permissions one, matching the rest of the suite.\n\n- Correct @since on the namespaceInstantiation additions (JexlFeatures,    JexlOptions) from stale 3.6 to 3.7.1, and RecordGetExecutor from 3.7.2 to 3.7.1, matching the actual in-flight version.\n- Reorder actions within each changes.xml section by descending JEXL issue number.\n"
    },
    {
      "commit": "ded79221a3a9dfb4090c22aae3c8ea68cc621d92",
      "tree": "be79f3f2c9fe64f6535fd9db3e89a6c20cfb230c",
      "parents": [
        "2b997c1df6b91ab6866d9d66bd3ca3d82e7947d3"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 14:47:43 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Sep 14 14:47:43 2026 +0200"
      },
      "message": "[JEXL-472] Consolidate record reflection into ClassTool, fix test fixture\n\nMove the Class#isRecord()/getRecordComponents() reflection out of\nRecordGetExecutor and into the existing ClassTool backport utility,\nresolved via MethodHandle to match how it already backports Java 9+\nmodule reflection, instead of duplicating a separate Method-based\nlookup.\n\nFix RecordPropertyAccessTest\u0027s on-the-fly compiled record fixture to\nactually compile into org.apache.commons.jexl3 (it previously compiled\nwith no package, then looked itself up under that package, which does\nnot resolve). Also switch the test to extend JexlTestCase and use the\nshared restricted-permissions engine instead of a bespoke\nUNRESTRICTED-permissions one, matching the rest of the suite.\n\nBuilds on the record accessor support originally proposed by\nAurelien Mino in #415.\n\nCo-Authored-By: Claude Code \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "2b997c1df6b91ab6866d9d66bd3ca3d82e7947d3",
      "tree": "af2cfd7449c88ffb04264a9b42ac1bdbfd9c494d",
      "parents": [
        "14fce3a65e743d3395cf439f8006b1940da71ad3"
      ],
      "author": {
        "name": "Aurélien Mino",
        "email": "aurelien.mino@gmail.com",
        "time": "Mon Sep 14 08:14:40 2026 +0200"
      },
      "committer": {
        "name": "Aurélien Mino",
        "email": "aurelien.mino@gmail.com",
        "time": "Mon Sep 14 08:14:40 2026 +0200"
      },
      "message": "Resolve record component accessors in property access\n\nfoo.bar never resolved to a record\u0027s generated bar() accessor, only\nto getBar()/isBar(), a public field, or duck-typed get(Object). Add a\nRecordGetExecutor that matches property to record component and\nlets Introspector resolve the actual accessor Method, so it still\ngoes through the usual permission checks.\n\nDetection is done entirely via reflection (Class#isRecord(),\nClass#getRecordComponents()) since this module still targets Java 8;\non such a runtime these methods simply don\u0027t exist and discovery\nquietly reports no match.\n\nThe new test compiles its record fixtures on the fly with\njavax.tools.JavaCompiler and skips itself below Java 16, since\n\u0027record\u0027 isn\u0027t valid syntax at this module\u0027s source level either.\n"
    },
    {
      "commit": "14fce3a65e743d3395cf439f8006b1940da71ad3",
      "tree": "f216795c6f6cfc63a15806f80316a039b645f943",
      "parents": [
        "a60740ee9f78c26d7a284eedd819de5a2fea66ee"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Sep 07 10:37:40 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Sep 07 10:37:40 2026 -0400"
      },
      "message": "Bump org.apache.commons:commons-parent from 104 to 105.\n"
    },
    {
      "commit": "a60740ee9f78c26d7a284eedd819de5a2fea66ee",
      "tree": "a79f426a132e506244a7de9c748d383ac17eb921",
      "parents": [
        "73fbe48ec3959833015567d2cb165f46ef1d194a",
        "4e64e3cb8bd355a3fe2b89d5c0bc527536d4ed7c"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Mon Aug 31 19:15:01 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 19:15:01 2026 +0200"
      },
      "message": "Merge pull request #414 from apache/JEXL-471\n\nJEXL-471: Runtime hardening: Constrain BigInteger operations and ensure regex interruptibility"
    },
    {
      "commit": "4e64e3cb8bd355a3fe2b89d5c0bc527536d4ed7c",
      "tree": "8e62761786072644c04ac4aa04e9488d33c42fd9",
      "parents": [
        "5788b85546430315dac17b2ec8ef17e4b06bff12"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Aug 31 15:53:53 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Aug 31 15:53:53 2026 +0200"
      },
      "message": "JEXL-471 : fix review comments, last take.\n"
    },
    {
      "commit": "5788b85546430315dac17b2ec8ef17e4b06bff12",
      "tree": "f13c9e7eaf327fa0001f3b72d732220c35e2f0c3",
      "parents": [
        "833ea619b396d9ed059a9fe4f6b061666b87f203"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Mon Aug 31 14:25:57 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 14:25:57 2026 +0200"
      },
      "message": "JEXL-471 : Apply batched suggestions from code review (take 2)\n\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e"
    },
    {
      "commit": "73fbe48ec3959833015567d2cb165f46ef1d194a",
      "tree": "ffb5981dfad32fee298e7d3280daf5c6e90dffcc",
      "parents": [
        "cff828c46600d42e19264a425096ecfbae851bd5"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Aug 31 11:18:55 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Aug 31 11:18:55 2026 +0000"
      },
      "message": "Bump github/codeql-action/analyze from 4.37.8 to 4.37.9.\n"
    },
    {
      "commit": "833ea619b396d9ed059a9fe4f6b061666b87f203",
      "tree": "01a04741982b82bfab112774b65e85405d34a580",
      "parents": [
        "4e6c8bfc3c6d9667b6fd45929a0e0a510b61783f"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Mon Aug 31 13:17:14 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 31 13:17:14 2026 +0200"
      },
      "message": "JEXL-471 : Potential fix for pull request finding\n\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e"
    },
    {
      "commit": "4e6c8bfc3c6d9667b6fd45929a0e0a510b61783f",
      "tree": "d526dd72cee1dd4b8e331dfb4e3ce655d02ddf94",
      "parents": [
        "b60d958a61a671e32453bf49d8c3ba4f8cc2c6a3"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Aug 31 13:08:27 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Aug 31 13:08:27 2026 +0200"
      },
      "message": "[JEXL-471] Complete double-check locking pattern in Pattern cache\n\nProper double-check locking: first volatile read without lock, compile\nPattern outside lock, then synchronized recheck-and-set to minimize\ncontention and avoid duplicate compilations when same script runs concurrently.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "b60d958a61a671e32453bf49d8c3ba4f8cc2c6a3",
      "tree": "4b762a5d1a5fd683b0899ed2448c0a38236456bc",
      "parents": [
        "964d8e7386871641a9c8a5162db2a2ffebdb8528"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Aug 31 11:07:28 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Mon Aug 31 12:56:08 2026 +0200"
      },
      "message": "JEXL-471 : fix review comments;\n"
    },
    {
      "commit": "964d8e7386871641a9c8a5162db2a2ffebdb8528",
      "tree": "72c630af06e2f003ecbc470ebaf1c937fc3d7d17",
      "parents": [
        "cff828c46600d42e19264a425096ecfbae851bd5"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Sun Aug 30 13:27:59 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Sun Aug 30 16:40:12 2026 +0200"
      },
      "message": "JEXL-471 : Runtime hardening: Constrain BigInteger operations and ensure regex interruptibility\n\n1. Make regex matching (\u003d~ operator) interruptible\n   * Wrap matched string in InterruptibleCharSequence\n   * Samples Thread.isInterrupted() every 256 chars\n   * Throws ArithmeticException -\u003e JexlException.Cancel on interruption\n   * Add length guard on regex patterns (max 2048 chars)\n\n2. Enforce MathContext precision on BigInteger arithmetic\n   * Move checkBigIntegerPrecision() outside try-catch in add()/subtract()/etc\n   * Prevent ArithmeticException from being silently swallowed\n   * Bounded results prevent memory exhaustion\n\n3. Prevent O(n²) DoS from huge BigInteger literals at parse time\n   * Cap literal digit count by MathContext.getPrecision()\n   * Fallback to hardcoded 256-digit limit if no precision configured\n   * NumberFormatException wraps as JexlException.Parsing\n\nTests added:\n   * testRegexMatchingInterruptible()\n   * testRegexPatternTooLong()\n   * testBigIntegerArithmeticPrecisionCap()\n   * testBigIntegerLiteralTooLong()\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "cff828c46600d42e19264a425096ecfbae851bd5",
      "tree": "efd7c0816a59aff1efbe58df44b1ca6b00bcc30a",
      "parents": [
        "175f5323ee6a8565d789c9ce1a1d2a723c6ab947"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Aug 27 13:41:41 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Aug 27 13:41:41 2026 -0400"
      },
      "message": "Bump actions/setup-java from 5.7.0 to 6.0.0.\n"
    },
    {
      "commit": "175f5323ee6a8565d789c9ce1a1d2a723c6ab947",
      "tree": "0fe43a41467d0ee2aea83f570908a64bb53403d9",
      "parents": [
        "46962260500266df56e120cf3cd746d3ee237522"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Aug 25 14:14:07 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Aug 25 14:14:07 2026 -0400"
      },
      "message": "Bump github/codeql-action/init from 4.37.7 to 4.37.8\n"
    },
    {
      "commit": "46962260500266df56e120cf3cd746d3ee237522",
      "tree": "d419207401f9e86a9a04553da8942e511f6dfaf9",
      "parents": [
        "5e340cba109cbaad2863c90f52459611a3498cd4",
        "e1cc1e57a55271510111a5c8a33c9f9aa496222a"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Tue Aug 25 18:27:49 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 18:27:49 2026 +0200"
      },
      "message": "Merge pull request #413 from apache/JEXL-468b\n\n[JEXL-468] Preserve deny-all package semantics when compose() adds class-specific exceptions"
    },
    {
      "commit": "e1cc1e57a55271510111a5c8a33c9f9aa496222a",
      "tree": "d419207401f9e86a9a04553da8942e511f6dfaf9",
      "parents": [
        "86ea6a3e36a487c69fe01f869e761340e7a6f917"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 17:42:53 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 17:42:53 2026 +0200"
      },
      "message": "[JEXL-468] Refactor PermissionsParser: extract mergePackage, fix readSpaces, add isDenyAll()\n\n- Fix readSpaces() returning `offset` instead of `i` (iterated one character at\n  a time through whitespace runs instead of skipping them in one shot)\n- Add NoJexlPackage.isDenyAll() virtual method (overridden true in DenyAllPackage\n  and the NOJEXL_PACKAGE singleton) to replace instanceof / identity checks\n- Extract the packages.compute() lambda into a static mergePackage(existing, deny,\n  denyAll) factory; the tri-state sign logic (null / true / false) stays in the\n  lambda where `p` is available, so mergePackage takes plain booleans with no\n  nullable parameters\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "86ea6a3e36a487c69fe01f869e761340e7a6f917",
      "tree": "9e58515f6cba2bb80bcd34286e7481a3cb259dc2",
      "parents": [
        "5e340cba109cbaad2863c90f52459611a3498cd4"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 17:13:22 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 17:14:21 2026 +0200"
      },
      "message": "[JEXL-468] Preserve deny-all package semantics when compose() adds class-specific exceptions\n\nWhen a package was previously marked as NOJEXL_PACKAGE (whole-package denial, e.g.\n\"com.example.internal {}\") and compose() is called with rules that add class-specific\nexceptions to that same package, the NOJEXL_PACKAGE sentinel was replaced by a plain\nNoJexlPackage whose getNoJexl() returns null for unlisted classes — causing deny(Class)\nto fall back to JEXL_CLASS (allow) for every class not explicitly mentioned.\n\nAdd DenyAllPackage as the symmetric counterpart of JexlPackage: it returns NOJEXL_CLASS\nfor any class not explicitly listed, so the deny-all-unlisted semantics of the base are\npreserved while individually declared exceptions (\"+SafeClass {}\") are honoured.\n\nPermissionsParser.readPackages() creates a DenyAllPackage (instead of NoJexlPackage)\nwhen merging rules into a package that was previously NOJEXL_PACKAGE or DenyAllPackage\nand no explicit polarity sign was given in the compose source.\n\nCo-Authored-By: Claude \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "5e340cba109cbaad2863c90f52459611a3498cd4",
      "tree": "2105ca0feddd302d78495bd0c3752f003eb4b07d",
      "parents": [
        "28b91ced57bc8fde6296726dcf511ce1a893aa26"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 16:03:39 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 16:03:39 2026 +0200"
      },
      "message": "[doc] Update changes.xml for JEXL-468, JEXL-469, JEXL-470\n"
    },
    {
      "commit": "28b91ced57bc8fde6296726dcf511ce1a893aa26",
      "tree": "050568c90b137cfd3f2a71d44a6831e1e7b96f20",
      "parents": [
        "99426ef3cfe87f77bdd762d130e442bdef66fa62",
        "ea2c4b853a456231cd0317f5c560a6290f10c9e5"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Tue Aug 25 15:53:53 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 15:53:53 2026 +0200"
      },
      "message": "Merge pull request #412 from apache/JEXL-470\n\n[JEXL-470] Fix several parser and interpreter correctness issues"
    },
    {
      "commit": "ea2c4b853a456231cd0317f5c560a6290f10c9e5",
      "tree": "050568c90b137cfd3f2a71d44a6831e1e7b96f20",
      "parents": [
        "99426ef3cfe87f77bdd762d130e442bdef66fa62"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Thu Aug 20 12:07:54 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 15:49:46 2026 +0200"
      },
      "message": "[JEXL-470] Parser/string correctness fixes\n\nTier-2 B2 wave — small, well-scoped parser and interpreter correctness fixes:\n\n- f018 StringParser.readUnicodeChar: reject \u0027g\u0027/\u0027h\u0027 as hex digits (was\n  `c \u003c\u003d \u0027h\u0027` / `c \u003c\u003d \u0027H\u0027`); only 0-9/a-f/A-F are valid, so `\\ug000` now\n  passes through literally instead of decoding a bogus char.\n- f020 Parser.jjt ArrayAccess: key the safe-navigation bit off the bracket\n  (child) index rather than the count of `?[` tokens, and saturate past 64\n  brackets, so `a[b]?[c]` marks the correct child. Parser regenerated.\n- f019 ASTRegexLiteral/StringParser: pass regex bodies through verbatim\n  (only translating `\\/` -\u003e `/`) so regex escapes like \\b, \\d, \\w survive;\n  wrap Pattern.compile in try/catch -\u003e JexlException.Parsing; add\n  escapeRegex as the round-trip inverse used by the Debugger.\n- f028 Interpreter empty()/size(): always rethrow JexlException.Cancel and,\n  in a strict engine, rethrow other errors instead of mapping them to\n  true/0 (which silently swallowed failures, including cancellation).\n- f029 Interpreter switch statement: let `continue` propagate to the\n  enclosing loop (as in Java) instead of being swallowed and falling\n  through into following cases.\n\nAlso fixes a checkstyle import-order violation in\nPermissionsRestrictedSweepTest introduced by the earlier hardening commit.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "99426ef3cfe87f77bdd762d130e442bdef66fa62",
      "tree": "0294e6311c52d032cdff826215d93c3f39d7e6cd",
      "parents": [
        "8df14514af2dbc79df8fca049ffc6e9551576cae",
        "65a036f7ed5530f6a144698eac30aca9d60d1266"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Tue Aug 25 15:26:22 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 15:26:22 2026 +0200"
      },
      "message": "Merge pull request #411 from apache/JEXL-469\n\n[JEXL-469] Add namespaceInstantiation feature"
    },
    {
      "commit": "65a036f7ed5530f6a144698eac30aca9d60d1266",
      "tree": "0294e6311c52d032cdff826215d93c3f39d7e6cd",
      "parents": [
        "8df14514af2dbc79df8fca049ffc6e9551576cae"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Thu Aug 20 11:27:49 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 15:22:39 2026 +0200"
      },
      "message": "[JEXL-469] Add namespaceInstantiation feature knob\n\nExpose JexlFeatures.namespaceInstantiation(boolean) to gate the reflective\nauto-instantiation of a namespace functor from a class or class-name binding\nin InterpreterBase.resolveNamespace. Default enabled (preserves behavior).\n\nThe gate lives at evaluation time and reads JexlOptions, so the parse-time\nfeature is bridged into JexlOptions at Engine construction and in evalOptions\n(downgrade-only), mirroring the existing lexical bridge.\n\nWhen disabled, a Class/String namespace is used for static methods only; no\nconstructor is invoked. Also folds in f047: a String namespace resolved to a\nclass for static methods now goes through the permission-aware\nuberspect.getClassByName, throwing \"no such class namespace\" when the class is\ndenied or cannot be located, instead of loading it unmediated.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "8df14514af2dbc79df8fca049ffc6e9551576cae",
      "tree": "7198de0317faff498c382a22afe5c83398dbdc7f",
      "parents": [
        "bcd5079648a31d0b40153591d5cbca891484f74c",
        "759ebaa2eaa20497bfb83a02272197f82e0d4a38"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Tue Aug 25 14:50:33 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 14:50:33 2026 +0200"
      },
      "message": "Merge pull request #410 from apache/JEXL-468\n\nJEXL-468 :  Harden introspection permissions \u0026 features"
    },
    {
      "commit": "759ebaa2eaa20497bfb83a02272197f82e0d4a38",
      "tree": "f4cd919e3acb968cfa8afd90552697cda72c1a73",
      "parents": [
        "5f4c69acff1dbcb91b56e35c11e3094dbd5d9e0b"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Tue Aug 25 14:43:49 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 14:43:49 2026 +0200"
      },
      "message": "Apply suggestions from code review\n\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e"
    },
    {
      "commit": "5f4c69acff1dbcb91b56e35c11e3094dbd5d9e0b",
      "tree": "22604a4855ca69e2b1c8afb53c14b13117a0700b",
      "parents": [
        "4c2a109c2d2028bbdda5b08862fbb70d9a1c52b9"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Thu Aug 20 11:42:21 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 14:29:35 2026 +0200"
      },
      "message": "[JEXL-468] Sandbox iterator gate, permission-parser polarity, engine-compiler denial\n\nf006: SandboxUberspect.getIterator delegated straight to the base uberspect,\nbypassing the sandbox. Route iteration through the sandbox by consulting the\n\"iterator\" method permission for the object\u0027s class; deny (null iterator, an\nempty loop) when it is blocked.\n\nf008: PermissionsParser mixed +/- polarity handling. A \u0027+\u0027 before a member\nmutated the class-scoped deny flag even after the class was created, leaking\nthe flipped polarity into a following inner class; an inner-class sign was\ndiscarded (the outer polarity leaked in instead). Now \u0027+\u0027 only selects an\nallowing class when it prefixes the class name, an inner class takes its own\npolarity from its explicit sign, and mixing +/- on one element is a parse error.\n\nf009/f036: deny the second-stage compiler surface under RESTRICTED - the\ncreateScript/createExpression/createJxltEngine methods on JexlEngine, the\ngetThreadEngine/setThreadContext thread-locals, and createExpression/\ncreateTemplate on JxltEngine - so a script holding a live engine cannot compile\nand run further scripts. Document the lambda-invocation bypass caveat.\n\nf007: document the JexlArithmetic operator fast-path exemptions (equals,\ncompareTo, toString, isEmpty, size, contains are invoked directly, not through\nthe permission-gated uberspect) on the JexlPermissions javadoc.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "4c2a109c2d2028bbdda5b08862fbb70d9a1c52b9",
      "tree": "714449bb20f9be8a6b4d95cc354b60f8ac5abb78",
      "parents": [
        "c28ff112a7bf2fa3e304c7ecca5a11216724a128"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Thu Aug 20 09:56:23 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Tue Aug 25 14:29:35 2026 +0200"
      },
      "message": "[JEXL-468] Harden introspection permissions and parser feature enforcement\n\nTier-1 security-scan remediations:\n\n- allow(Method) now recurses into parent interfaces so a @NoJexl on a\n  super-interface method is honored through derived interfaces.\n- compose() preserves base allow/deny markers instead of degrading them\n  when merging permission sets.\n- JXLT/template sub-parsers now bracket their own JexlFeatures in\n  parse()/cleanup(), so embedded ${...}/#{...} fragments are parsed under\n  the requested feature set rather than the controller\u0027s last state.\n- Expanded RESTRICTED/SECURE deny-lists (ProcessHandle, Module/ModuleLayer,\n  Locale/TimeZone.setDefault, parallel streams, blocking sync primitives,\n  Timer, direct buffers, ...) and added a NOJEXL_CONTAINER marker plus\n  nested-class tracking so empty container blocks do not over-propagate\n  denial to nested declarations.\n- Moved the UNRESTRICTED singleton into the Markers holder to break a\n  class-init NPE cycle (JLS 12.4.2 superinterface default-method init).\n\nAdds regression tests: PermissionsInitOrderTest, JxltFeatureEnforcementTest,\nPermissionsRestrictedSweepTest, plus assertions in ComposePermissionsTest\nand NoJexlTest.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\n"
    },
    {
      "commit": "bcd5079648a31d0b40153591d5cbca891484f74c",
      "tree": "d9af72504a0761bae808fa0508a7722a245673d2",
      "parents": [
        "c28ff112a7bf2fa3e304c7ecca5a11216724a128"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Aug 22 09:42:39 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Aug 22 09:42:39 2026 -0400"
      },
      "message": "Bump org.apache.commons:commons-parent from 103 to 104.\n"
    },
    {
      "commit": "c28ff112a7bf2fa3e304c7ecca5a11216724a128",
      "tree": "c0223f7ea13672629e59f5fb99829b0fb0189c9a",
      "parents": [
        "9c3ab070ed96449fcf335621ee9182f35ba3b508"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Aug 18 16:01:33 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Aug 18 16:01:33 2026 -0400"
      },
      "message": "Bump codeql-action from 4.37.6 to 4.37.7\n"
    },
    {
      "commit": "9c3ab070ed96449fcf335621ee9182f35ba3b508",
      "tree": "8e13b301daf278cb132500dd055e0cb0329874f0",
      "parents": [
        "d0a99192247249cb49e7b2c66597ea6884f82ec5"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Aug 12 15:56:46 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Aug 12 15:56:46 2026 +0200"
      },
      "message": "JEXL : skip findbugs on Java28+\n"
    },
    {
      "commit": "d0a99192247249cb49e7b2c66597ea6884f82ec5",
      "tree": "75568f1ead42b2e522c29f357ae9e679a6daa12b",
      "parents": [
        "9b0c5869b91c40936ceb98dbf9f5da52b06fc5a6"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Aug 12 15:49:19 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Aug 12 15:49:19 2026 +0200"
      },
      "message": "JEXL : skip jacoco on Java28+\n"
    },
    {
      "commit": "9b0c5869b91c40936ceb98dbf9f5da52b06fc5a6",
      "tree": "416bf365a61a8107877ed10b74b942fa5f5e75c0",
      "parents": [
        "a7a3a84b75a043c367988643cdd7fba6716c110d",
        "fecd3ad7325748fdd19aa3411d051e87b830e685"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Wed Aug 12 15:47:12 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 12 15:47:12 2026 +0200"
      },
      "message": "Merge pull request #409 from NikRom5531/JEXL-411-leading-zeroes\n\n[JEXL-411] Allow optional leading zeroes in floating point literals"
    },
    {
      "commit": "fecd3ad7325748fdd19aa3411d051e87b830e685",
      "tree": "416bf365a61a8107877ed10b74b942fa5f5e75c0",
      "parents": [
        "c8cd40fc1a4958cb10081bc5192ab6b05fb50df1"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Aug 12 14:30:17 2026 +0200"
      },
      "committer": {
        "name": "Romanov N.A.",
        "email": "kolya-2012@mail.ru",
        "time": "Wed Aug 12 16:06:36 2026 +0300"
      },
      "message": "JEXL-411: move isAllDigits to JexlParser;\n- update changes.xml;\n"
    },
    {
      "commit": "c8cd40fc1a4958cb10081bc5192ab6b05fb50df1",
      "tree": "5974e8733092165029af39fe7f9ae30426628d66",
      "parents": [
        "a7a3a84b75a043c367988643cdd7fba6716c110d"
      ],
      "author": {
        "name": "Romanov N.A.",
        "email": "kolya-2012@mail.ru",
        "time": "Wed Aug 12 13:24:23 2026 +0300"
      },
      "committer": {
        "name": "Romanov N.A.",
        "email": "kolya-2012@mail.ru",
        "time": "Wed Aug 12 13:24:23 2026 +0300"
      },
      "message": "JEXL-411: Allow optional leading zeroes in floating point literals\n\nJEXL could not parse a floating point literal with an omitted leading\nzero (e.g. \".1\"), so \"(1+0.1)*2\" evaluated to 2.2 while \"(1+.1)*2\"\nraised a parsing error, although \".1\" is valid in Java.\n\nA leading-dot number is tokenized as \"DOT DOT_IDENTIFIER\", which is\nidentical to the postfix index access \"x.3\". The literal is therefore\nrecognized in the parser, in operand position, rather than at the\nlexer level. FloatLiteral() now also accepts \".\u003cdigits\u003e\" (only\nall-digit DOT_IDENTIFIER images, checked via isAllDigits) and rebuilds\nthe value as \".\" + image before handing it to NumberParser. Dot-based\nindex/property access is left untouched.\n\nAdd an arithmetic test covering the JEXL-411 reproduction, leading-dot\nliterals, unary sign and the index-access regression.\n"
    },
    {
      "commit": "a7a3a84b75a043c367988643cdd7fba6716c110d",
      "tree": "3a65dbd70b5d73a74a649201c27b9538b7b7cd3d",
      "parents": [
        "c5520e64d13d5496e98e60c04d4b998e5da3bb19"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Aug 05 14:14:23 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Aug 05 14:14:23 2026 -0400"
      },
      "message": "Bump actions/setup-java from 5.6.0 to 5.7.0\n"
    },
    {
      "commit": "c5520e64d13d5496e98e60c04d4b998e5da3bb19",
      "tree": "122f930e1926ec94253657b17089f85a665522f0",
      "parents": [
        "60cbb54456bd26175eb210f901d1474707340e3e"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Aug 04 15:58:51 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Aug 04 15:58:51 2026 -0400"
      },
      "message": "Bump github/codeql-action from 4.37.3 to 4.37.6.\n"
    },
    {
      "commit": "60cbb54456bd26175eb210f901d1474707340e3e",
      "tree": "5ad24c7ae71e88dc90da632da35507f6accb71ce",
      "parents": [
        "ecb77121674c6bab048d123c408ec9f5d2674cf9"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Aug 02 15:55:12 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Aug 02 15:55:12 2026 -0400"
      },
      "message": "Javadoc\n"
    },
    {
      "commit": "ecb77121674c6bab048d123c408ec9f5d2674cf9",
      "tree": "2b955778c58c5ebd2a237a869df94ba537fe9081",
      "parents": [
        "e1527bc32e5a137fe0a2d7aad0a6648af6e4659e"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 29 08:14:25 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 29 08:14:25 2026 -0400"
      },
      "message": "Bump ossf/scorecard-action from 2.4.3 to 2.4.4.\n"
    },
    {
      "commit": "e1527bc32e5a137fe0a2d7aad0a6648af6e4659e",
      "tree": "1caffef25bfcaa202079f0ea2aa708c4db7e91a1",
      "parents": [
        "4d32e29e1cf6c5ffef34a8bac412f460791c8940"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jul 28 14:54:15 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jul 28 14:54:15 2026 -0400"
      },
      "message": "Bump github/codeql-action from 4.37.1 to 4.37.3\n"
    },
    {
      "commit": "4d32e29e1cf6c5ffef34a8bac412f460791c8940",
      "tree": "2b055d9a626378be9d0e2d60a45b7237a8ca5458",
      "parents": [
        "2f2608145db52c76db6af6581a5d5a72c07e28ab"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 25 12:21:38 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 25 12:21:38 2026 -0400"
      },
      "message": "Update GH CI Java versions.\n"
    },
    {
      "commit": "2f2608145db52c76db6af6581a5d5a72c07e28ab",
      "tree": "03d3f65006f8f702d38fb76f7717dc9872c23c60",
      "parents": [
        "f83b73f353c38e3fcc7d8fae10e429169dc9b71c"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 25 12:20:53 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 25 12:20:53 2026 -0400"
      },
      "message": "Update GH CI Java versions.\n"
    },
    {
      "commit": "f83b73f353c38e3fcc7d8fae10e429169dc9b71c",
      "tree": "e8d3873349cdc3e7638f8ba4eeb4fe758e1082f9",
      "parents": [
        "c0b850195aab78c392f7c809ec3afbe50f799961"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 25 09:49:44 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 25 09:49:44 2026 -0400"
      },
      "message": "Bump actions/checkout from 7.0.0 to 7.0.1\n"
    },
    {
      "commit": "c0b850195aab78c392f7c809ec3afbe50f799961",
      "tree": "326a5894815b3a989971665952eb8d97255284ab",
      "parents": [
        "5f294331c45f140c8f012659ebec768bf5d4f6fa"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jul 24 15:32:31 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jul 24 15:32:31 2026 +0200"
      },
      "message": "JEXL-466: ensure JexlEngine is thread-local accessible when creating TemplateScript and TemplateExpressions;\n"
    },
    {
      "commit": "5f294331c45f140c8f012659ebec768bf5d4f6fa",
      "tree": "2085764bf8e8ca6bc10b4099911141ec074381e8",
      "parents": [
        "c2afbfb6e91fa720bbc9010f749d977a612067cd"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jul 24 12:28:47 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jul 24 12:28:47 2026 +0200"
      },
      "message": "JEXL-467: TextMate JEXL bundle;\n"
    },
    {
      "commit": "c2afbfb6e91fa720bbc9010f749d977a612067cd",
      "tree": "27e96da9bd6065ecbdadb0baf4abe7bc267ddc22",
      "parents": [
        "765d80bf532949787505fec68d1d0aa3657750a5"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 22 15:15:02 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 22 15:15:02 2026 -0400"
      },
      "message": "Add messages when throwing NullPointerException.\n"
    },
    {
      "commit": "765d80bf532949787505fec68d1d0aa3657750a5",
      "tree": "8f2f2f17c0b488fb16e2222a3c96006044f9e1db",
      "parents": [
        "77041ecd665af63b18f45cbdf699a2ec88976274"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 22 15:13:55 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 22 15:13:55 2026 -0400"
      },
      "message": "Add messages when throwing NullPointerException.\n"
    },
    {
      "commit": "77041ecd665af63b18f45cbdf699a2ec88976274",
      "tree": "553c33de7bdfb5cb05d20344840cc33196ebffab",
      "parents": [
        "0fbd4011d9d8831ef97f79ba16280a45f0d37744"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 22 05:18:35 2026 -0700"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 22 05:18:35 2026 -0700"
      },
      "message": "Bump org.apache.commons:commons-parent from 102 to 103.\n"
    },
    {
      "commit": "0fbd4011d9d8831ef97f79ba16280a45f0d37744",
      "tree": "5ecb7284c78779d9b6529bea261ba0182eaa023d",
      "parents": [
        "dcb15ab8982a715e33c0b8e36d9b2c741ea46802"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jul 21 13:45:41 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jul 21 13:45:41 2026 -0400"
      },
      "message": "Bump github/codeql-action from 4.37.0 to 4.37.1\n"
    },
    {
      "commit": "dcb15ab8982a715e33c0b8e36d9b2c741ea46802",
      "tree": "5acda9575e2a04111e0db3f80d73fb946e23d10a",
      "parents": [
        "b9554ecd28e819fcbaaf2b06007477992b06462f"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jul 21 11:45:56 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jul 21 11:45:56 2026 -0400"
      },
      "message": "Bump actions/setup-java from 5.5.0 to 5.6.0\n"
    },
    {
      "commit": "b9554ecd28e819fcbaaf2b06007477992b06462f",
      "tree": "967402a2802b2f355def7849d787662a4401db37",
      "parents": [
        "1df43a52001d2bae4ddf7d0df580f0053053a9c9"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Jul 13 13:49:54 2026 -0700"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Jul 13 13:49:54 2026 -0700"
      },
      "message": "Bump actions/setup-java from 5.4.0 to 5.5.0\n"
    },
    {
      "commit": "1df43a52001d2bae4ddf7d0df580f0053053a9c9",
      "tree": "1e1f1a9478df3b4a4ec579699b70998d7fd4d952",
      "parents": [
        "792570d9944fff297c9036a5c10ea298afa49bcb"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 11 11:22:29 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 11 11:22:29 2026 -0400"
      },
      "message": "Javadoc\n"
    },
    {
      "commit": "792570d9944fff297c9036a5c10ea298afa49bcb",
      "tree": "d3964b63fb68a034a3bee8cf777af920f1ed372c",
      "parents": [
        "4d4917219a45f2d9b68a6c1e312448c71ac30238"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 11 09:08:53 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 11 09:08:53 2026 -0400"
      },
      "message": "Javadoc\n"
    },
    {
      "commit": "4d4917219a45f2d9b68a6c1e312448c71ac30238",
      "tree": "d3d8de431976b301a9203849c947634605f3b9e2",
      "parents": [
        "199c84b44b706f2684e838b667b714496210965d"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 11 08:50:53 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 11 08:50:53 2026 -0400"
      },
      "message": "Javadoc\n"
    },
    {
      "commit": "199c84b44b706f2684e838b667b714496210965d",
      "tree": "be3c6a1777262d9c878273994fe22b6d597c05f9",
      "parents": [
        "5a184d29fc61323bddf870c97ac53eba9e292f53"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Fri Jul 10 09:08:45 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Fri Jul 10 09:08:45 2026 -0400"
      },
      "message": "Bump github/codeql-action from 4.36.3 to 4.37.0\n"
    },
    {
      "commit": "5a184d29fc61323bddf870c97ac53eba9e292f53",
      "tree": "d4f533d21299a75b367cf2954d19febc6c13c5ac",
      "parents": [
        "7d5e48e2214f8a002e0e23aece85cdf3a7150898"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 08 16:14:59 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 08 16:14:59 2026 -0400"
      },
      "message": "Bump github/codeql-action from 4.36.2 to 4.36.3\n"
    },
    {
      "commit": "7d5e48e2214f8a002e0e23aece85cdf3a7150898",
      "tree": "7048ce116eb9c108749ad72079e33bacaa5ec50f",
      "parents": [
        "7cf74b81d84a9061013addac0182c013f4b7c1a3"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jul 05 09:39:43 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jul 05 09:39:43 2026 -0400"
      },
      "message": "Flip null test\n"
    },
    {
      "commit": "7cf74b81d84a9061013addac0182c013f4b7c1a3",
      "tree": "07ec18c96f0a9ee1e0981cb88248d0f4536343f3",
      "parents": [
        "c9ede1bac718ddb414bdd86e79f56a7fc90129be"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 04 19:22:48 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sat Jul 04 19:22:48 2026 -0400"
      },
      "message": "Normalize spelling\n"
    },
    {
      "commit": "c9ede1bac718ddb414bdd86e79f56a7fc90129be",
      "tree": "c530e1d6e3d0b6f56d4a0e8da332ea2f23b65327",
      "parents": [
        "824c2690700184928ee8e39e420d51952c65da43"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 21:00:43 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 21:00:43 2026 +0000"
      },
      "message": "Fix typos.\n"
    },
    {
      "commit": "824c2690700184928ee8e39e420d51952c65da43",
      "tree": "733712dc65a6f9b1b0ec13bf13211b033bfecd8f",
      "parents": [
        "76594a80d85b4ce900b2b4fa9e68722a61389540"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 20:59:12 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 20:59:12 2026 +0000"
      },
      "message": "Updates for the next release\n"
    },
    {
      "commit": "76594a80d85b4ce900b2b4fa9e68722a61389540",
      "tree": "c8ee7a45cf3276afaf47f9998f290ab99ae3b7e0",
      "parents": [
        "f901652ac3d39a25bb415be001c4c7fdf5e75fab",
        "5bca2ad4f8cd112ecfdaaafd6cdfb2f2bf8ede7f"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 20:13:58 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 20:13:58 2026 +0000"
      },
      "message": "Merge branch \u0027release\u0027\n"
    },
    {
      "commit": "5bca2ad4f8cd112ecfdaaafd6cdfb2f2bf8ede7f",
      "tree": "3df5e85eff2ad1a17301fbacbb7211f4faf95b3d",
      "parents": [
        "21827925ba6f4fff46ffe4c1f6c4fd41abc663a9"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 20:13:57 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jul 02 20:13:57 2026 +0000"
      },
      "message": "Bump to next development version\n"
    },
    {
      "commit": "f901652ac3d39a25bb415be001c4c7fdf5e75fab",
      "tree": "decbee0840885c52165bd5d503b33eaefa736099",
      "parents": [
        "8cd85160f35007493fef2bb608051cd0df594648",
        "100a272bff19c982ed6fc85ed2d0ee87ade24af3"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@users.noreply.github.com",
        "time": "Wed Jul 01 08:13:21 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 01 08:13:21 2026 -0400"
      },
      "message": "Merge pull request #408 from apache/dependabot/github_actions/actions/checkout-7.0.0\n\nBump actions/checkout from 6.0.3 to 7.0.0"
    },
    {
      "commit": "8cd85160f35007493fef2bb608051cd0df594648",
      "tree": "bb08f5ed8b3c81cf9dec77c8b7f2b60f90feb9de",
      "parents": [
        "769154f4f12e0f1111a2df315213fb9e115d6c08"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 01 12:12:01 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jul 01 12:12:01 2026 +0000"
      },
      "message": "Pick up commons.jacoco.version from the parent POM.\n"
    },
    {
      "commit": "100a272bff19c982ed6fc85ed2d0ee87ade24af3",
      "tree": "e070819aa9d587b7d5beeb4988fa51b8f278198f",
      "parents": [
        "769154f4f12e0f1111a2df315213fb9e115d6c08"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 01 12:02:35 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 01 12:02:35 2026 +0000"
      },
      "message": "Bump actions/checkout from 6.0.3 to 7.0.0\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "769154f4f12e0f1111a2df315213fb9e115d6c08",
      "tree": "7c8c09735f9c7639087545b6e07d6f2a4384d8da",
      "parents": [
        "9a94643a94bb7235f9c9a04ba7e4f9812340339d"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 30 20:50:39 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 30 20:50:39 2026 -0400"
      },
      "message": "Bump actions/setup-java from 5.3.0 to 5.4.0\n"
    },
    {
      "commit": "9a94643a94bb7235f9c9a04ba7e4f9812340339d",
      "tree": "b93cc21a1221cabcd07766e5add48a155bc3a536",
      "parents": [
        "e9aa7876284e09962be88fa79d5047127563ab8e"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 30 14:02:28 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 30 14:02:28 2026 +0000"
      },
      "message": "Javadoc\n"
    },
    {
      "commit": "e9aa7876284e09962be88fa79d5047127563ab8e",
      "tree": "dd6ac9ff49288aae2ecc9d9c8091098463d248b5",
      "parents": [
        "66ae9f406de8b60a02ca2dad87b1fb7329ee8740"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Jun 29 07:30:25 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Jun 29 07:30:25 2026 -0400"
      },
      "message": "Bump actions/cache from 6.0.0 to 6.1.0\n"
    },
    {
      "commit": "21827925ba6f4fff46ffe4c1f6c4fd41abc663a9",
      "tree": "1e83f4bf1194190ef6f142aeeb9d0b93b7cc9965",
      "parents": [
        "66ae9f406de8b60a02ca2dad87b1fb7329ee8740"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:54:02 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:54:02 2026 +0000"
      },
      "message": "Prepare for the release candidate 3.7.0 RC1\n"
    },
    {
      "commit": "66ae9f406de8b60a02ca2dad87b1fb7329ee8740",
      "tree": "3d5bc4fd67cde0e4b6659f36187ce32758a41a9a",
      "parents": [
        "9211b29ab3fdd593a9a51f9093c62a6906b03405"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:51:53 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:51:53 2026 +0000"
      },
      "message": "Prepare for the next release candidate\n"
    },
    {
      "commit": "9211b29ab3fdd593a9a51f9093c62a6906b03405",
      "tree": "ec2b0762d995e7f47c096d706faeff8a5a385548",
      "parents": [
        "07299eba648eb7665d42b02cafa52c4ef50621a5"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:42:12 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:42:12 2026 +0000"
      },
      "message": "Use final.\n\n- Remove trailing whitespace.\n- Better local variable name.\n"
    },
    {
      "commit": "07299eba648eb7665d42b02cafa52c4ef50621a5",
      "tree": "6440e464c92bc73af3755a62495339650bec15c7",
      "parents": [
        "a82f5c6ec1489e6c200d206696b65f02be65c245"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:37:56 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 22:37:56 2026 +0000"
      },
      "message": "Use final\n\nUse vararg\n"
    },
    {
      "commit": "a82f5c6ec1489e6c200d206696b65f02be65c245",
      "tree": "8d422408d499e28d5be751b7bedb74d11aad47f2",
      "parents": [
        "dd2cdf98d05fdc6bf58d77ff9231a82aa801e167"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 12:02:11 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 12:02:11 2026 +0000"
      },
      "message": "Add back release notes for 3.6.4.\n"
    },
    {
      "commit": "dd2cdf98d05fdc6bf58d77ff9231a82aa801e167",
      "tree": "35f8495fa2be44e172570097f24e3c0f57e4797f",
      "parents": [
        "2fe7eebf3c0f291ad6ef458aa9df407bc0b9e4b7"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 11:31:39 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 11:31:39 2026 +0000"
      },
      "message": "Updates for the next release\n"
    },
    {
      "commit": "2fe7eebf3c0f291ad6ef458aa9df407bc0b9e4b7",
      "tree": "32b78b499cc11bcd88edd67cfe90e6d965556254",
      "parents": [
        "e785bebf3712987a42fe504f5f6b9843fc84ac97",
        "c5d2ffcd6a590e61ef027e5867c780551f395d3f"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 11:30:42 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 11:30:42 2026 +0000"
      },
      "message": "Bump to next development version\n"
    },
    {
      "commit": "c5d2ffcd6a590e61ef027e5867c780551f395d3f",
      "tree": "5af1881e2d814457b5aa54988f951d098f308544",
      "parents": [
        "022b5036898bd561795ad4110915a5242d125069"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 11:29:09 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Sun Jun 28 11:29:09 2026 +0000"
      },
      "message": "Bump to next development version\n"
    },
    {
      "commit": "e785bebf3712987a42fe504f5f6b9843fc84ac97",
      "tree": "4c02615c6082b713e07393ebab20dfde9243cddf",
      "parents": [
        "8873ccb938e236bbe8b6110a82547924bf23f228",
        "dbeb7a870c079dd4abdf1c5cd54dced294624c76"
      ],
      "author": {
        "name": "Henrib",
        "email": "henrib@apache.org",
        "time": "Sat Jun 27 16:16:24 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 27 16:16:24 2026 +0200"
      },
      "message": "Merge pull request #406 from apache/JEXL-465\n\nJEXL-465, JEXL-464, JEXL-463 : the 3.7.0 release improvements;"
    },
    {
      "commit": "dbeb7a870c079dd4abdf1c5cd54dced294624c76",
      "tree": "4c02615c6082b713e07393ebab20dfde9243cddf",
      "parents": [
        "2d0bafe32fbdb3e5684a36215a89bcb51373a03e"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 19:34:55 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 19:34:55 2026 +0200"
      },
      "message": "JEXL-465: addressing Gary\u0027s comments;\n"
    },
    {
      "commit": "2d0bafe32fbdb3e5684a36215a89bcb51373a03e",
      "tree": "09e92acfa7229b525102b769e5918a79f68284f8",
      "parents": [
        "b915e46d740ae622e4706dfece5200ac887a67c4"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 19:20:22 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 19:20:22 2026 +0200"
      },
      "message": "JEXL-465: harden permissions; improve docs and tests;\n- tighten SECURE/RESTRICTED to deny file, env, loader, thread access;\n- add NONE deny-all base and create() factory;\n- fix getClass() bypass in Permissions.allow(Class,Method);\n- add JexlBuilder.setDefaultOptions();\n- add security disclaimer in package-info.java and site index;\n- raise coverage: JexlConfigLoader option flags, LoggingPermissions;\n"
    },
    {
      "commit": "b915e46d740ae622e4706dfece5200ac887a67c4",
      "tree": "77c9f8fa9105b4fecba945b6fcc63ee6ad9bda09",
      "parents": [
        "1212144f7bed6e9630ff231fb82364c83caf420b"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 15:26:19 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 15:26:19 2026 +0200"
      },
      "message": "JEXL-465: checkstyle;\n"
    },
    {
      "commit": "1212144f7bed6e9630ff231fb82364c83caf420b",
      "tree": "2649ba70d307db7ac9d47c51eed21d2c2b5400e4",
      "parents": [
        "8873ccb938e236bbe8b6110a82547924bf23f228"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 15:14:27 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Fri Jun 26 15:14:27 2026 +0200"
      },
      "message": "JEXL-465, JEXL-464, JEXL-463 : the 3.7.0 release improvements;\n\n- SECURE permissions and hardened features become the default (no new, no global\n  side-effects, no pragmas/annotations; lexical on, loops kept for scripts); add\n  JexlBuilder.FULL and setDefaultFeatures to restore pre-3.7 behavior (JEXL-464)\n- add JexlConfigLoader to build an engine from YAML (JEXL-465)\n- add JexlPermissions.logging() to log allow/deny decisions; add SECURE constant (JEXL-463)\n"
    },
    {
      "commit": "8873ccb938e236bbe8b6110a82547924bf23f228",
      "tree": "f92fc6015dbe416da50f81953c75fd96cc4c1d44",
      "parents": [
        "eab0c5bbfe77389f64dfddaa26a5894382cf536a"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jun 25 18:24:28 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Thu Jun 25 18:24:28 2026 -0400"
      },
      "message": "Bump actions/cache from 5.0.5 to 6.0.0.\n"
    },
    {
      "commit": "022b5036898bd561795ad4110915a5242d125069",
      "tree": "f5f39d352536050c3b4fa25f9b95ea5db688f5cf",
      "parents": [
        "eab0c5bbfe77389f64dfddaa26a5894382cf536a"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jun 24 23:08:46 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jun 24 23:08:46 2026 +0000"
      },
      "message": "Prepare for the release candidate 3.6.4 RC1\n"
    },
    {
      "commit": "eab0c5bbfe77389f64dfddaa26a5894382cf536a",
      "tree": "d8c338e1294a34b9c54e703992e65da5d21eb247",
      "parents": [
        "edbf94b9faa779a0e9d03a66e6565b6bd1e22b12"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jun 24 23:05:34 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Wed Jun 24 23:05:34 2026 +0000"
      },
      "message": "Prepare for the next release candidate\n"
    },
    {
      "commit": "edbf94b9faa779a0e9d03a66e6565b6bd1e22b12",
      "tree": "023467736521fb912f0eb33eee48e23fdd2750e8",
      "parents": [
        "fe73af4d65c9b4c1bbe90b4951d6d10b75eb8053"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Jun 24 18:31:58 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Jun 24 18:31:58 2026 +0200"
      },
      "message": "JEXL-462 : release notes, etc.\n"
    },
    {
      "commit": "fe73af4d65c9b4c1bbe90b4951d6d10b75eb8053",
      "tree": "670bde4cfde5ee89c0c663871bbdb3b272d14ec8",
      "parents": [
        "2c900c8364c390e4953e4e8b55f09d143d979e29"
      ],
      "author": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Jun 24 17:50:01 2026 +0200"
      },
      "committer": {
        "name": "Henrib",
        "email": "hbiestro@gmail.com",
        "time": "Wed Jun 24 17:50:01 2026 +0200"
      },
      "message": "JEXL-462 : close RESTRICTED permission set; fix wildcard exposure\n- Replace all \u0027.*\u0027 wildcards in RESTRICTED with explicit \u0027+{}\u0027 package declarations so future JDK subpackages are never silently admitted.\n- Add missing safe packages (java.uti.function/stream/regex/concurrent.atomic, java.time.chrono/format/temporal/zone) and deny known hazards (ZoneRulesProvider, executor classes, java.util.zip/jar/prefs/logging via the closed-world boundary).\n- Extend the permissions engine: any explicit package declaration (positive or negative) now closes the world — only declared packages are accessible.\n- NoJexlPackage gains hasAllowedClass() to distinguish a deny-list (unlisted class \u003d allowed) from an allow-list (unlisted class \u003d denied), matching the semantics of \u0027java.lang { Runtime {} }\u0027 vs \u0027java.io -{ +PrintWriter{} }\u0027.\n"
    },
    {
      "commit": "2c900c8364c390e4953e4e8b55f09d143d979e29",
      "tree": "eceb303b18f83f497dc45918be1f24a39e4b0bb6",
      "parents": [
        "50f5924e9b39308aecbb495dbd78d00459b3eb14"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 23 22:58:01 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 23 22:58:01 2026 +0000"
      },
      "message": "Updates for the next release\n"
    },
    {
      "commit": "50f5924e9b39308aecbb495dbd78d00459b3eb14",
      "tree": "f7cdef62317a507b78080468a6c44b245b785987",
      "parents": [
        "cefce9cf2338bd884944e40c0a12961f3872dd6d"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 23 18:47:37 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 23 18:47:37 2026 +0000"
      },
      "message": "Updates for the next release\n"
    },
    {
      "commit": "cefce9cf2338bd884944e40c0a12961f3872dd6d",
      "tree": "17c22c425f117ad9f104504ecb09d14ea399a32a",
      "parents": [
        "6e9e0f8d91005d6093c050d197c60600ce073581"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 23 18:46:21 2026 +0000"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Tue Jun 23 18:46:21 2026 +0000"
      },
      "message": "Bump to next development version\n"
    },
    {
      "commit": "6e9e0f8d91005d6093c050d197c60600ce073581",
      "tree": "0bc24bbd96ff3ced61adfc0a979d008eb45d48a3",
      "parents": [
        "22c9343c1221b96f9c452ca35a657873610a05c8"
      ],
      "author": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Jun 22 07:32:37 2026 -0400"
      },
      "committer": {
        "name": "Gary Gregory",
        "email": "garydgregory@gmail.com",
        "time": "Mon Jun 22 07:32:37 2026 -0400"
      },
      "message": "Bump actions/setup-java from 5.2.0 to 5.3.0\n"
    }
  ],
  "next": "22c9343c1221b96f9c452ca35a657873610a05c8"
}
