1. 3d8e517 chore(asf.yaml): remove bypass_teams by lprimak · 30 hours ago main
  2. 4997ed3 chore(asf): properly format branch protection rule by lprimak · 9 days ago
  3. a1c4c27 Merge pull request #2701 from lprimak/add-branch-protection by Steinar Bang · 11 days ago
  4. 0c20f0d [CI] Add hook to validate dependabot.yml with pre-commit (#2716) by John Bampton · 11 days ago
  5. 59306da [CI] Add pre-commit hook to validate the CITATION file (#2717) by John Bampton · 11 days ago
  6. 092afb0 chore(deps-dev): bump org.apache.cxf:cxf-rt-frontend-jaxrs (#2721) by dependabot[bot] · 11 days ago
  7. 85cd5c4 chore(deps-dev): bump arquillian.core.version (#2722) by dependabot[bot] · 11 days ago
  8. 3aafcab chore(deps): bump the github-actions-dependencies group with 3 updates (#2723) by dependabot[bot] · 11 days ago
  9. dfd2930 chore(deps): bump org.apache.commons:commons-configuration2 (#2724) by dependabot[bot] · 11 days ago
  10. 772f17f chore(deps): bump org.omnifaces:omnifaces from 3.14.20 to 3.14.21 (#2725) by dependabot[bot] · 11 days ago
  11. e1a4128 chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin (#2727) by dependabot[bot] · 11 days ago
  12. 0aed6ee chore(deps): bump org.apache.cxf:cxf-bom from 3.6.10 to 3.6.11 (#2728) by dependabot[bot] · 11 days ago
  13. c9ee120 chore(deps): bump org.apache.cxf:cxf-rt-rs-client from 3.6.10 to 3.6.11 (#2729) by dependabot[bot] · 11 days ago
  14. 9063406 Using Rdn.escapeValues() by lprimak · 2 weeks ago
  15. 31fbdb8 Merge pull request #2698 from apache/dependabot/maven/org.apache.johnzon-johnzon-jsonb-1.3.0 by François Papon · 2 weeks ago
  16. dbad41a Merge pull request #2696 from apache/dependabot/github_actions/github-actions-dependencies-10fd86e523 by François Papon · 2 weeks ago
  17. 91a69dc Merge pull request #2697 from apache/dependabot/maven/log4j.version-2.26.0 by François Papon · 2 weeks ago
  18. 164cb1e Merge pull request #2702 from potiuk/asf-security/agents-md-security-link-2026-05-14 by François Papon · 2 weeks ago
  19. 9f35283 chore(deps): bump log4j.version from 2.25.4 to 2.26.0 by dependabot[bot] · 2 weeks ago
  20. be67698 Merge pull request #2694 from apache/dependabot/maven/slf4j.version-2.0.18 by François Papon · 2 weeks ago
  21. c589bb1 Merge pull request #2699 from apache/dependabot/maven/com.github.siom79.japicmp-japicmp-maven-plugin-0.25.7 by François Papon · 2 weeks ago
  22. eda4022 Merge pull request #2700 from apache/dependabot/maven/org.apache-apache-38 by François Papon · 2 weeks ago
  23. 2a1c4da chore: removed branch protection from main, update github ruleset to include additional branches by lprimak · 3 weeks ago
  24. b3c84a6 Update .asf.yaml by Lenny Primak · 3 weeks ago
  25. 9371115 [#2704] [#2710] Fixed Session fixation-related regressions (#2711) by Lenny Primak · 3 weeks ago
  26. a7265a1 chore(deps): bump org.apache.commons:commons-configuration2 (#2706) by dependabot[bot] · 3 weeks ago
  27. bd278bc enh(jakarta-ee): strip out the host part of the referer header by lprimak · 3 weeks ago
  28. c6af28c chore(deps): bump https://github.com/zizmorcore/zizmor-pre-commit (#2709) by dependabot[bot] · 3 weeks ago
  29. d7500f2 Switch pre-commit to ASF approved prek-action (#2705) by John Bampton · 3 weeks ago
  30. 2b9e8e0 minor fixes for SECURITY.md to reflect the true state of the docs by lprimak · 4 weeks ago
  31. a890040 Add AGENTS.md + SECURITY.md linking the project's security model by Jarek Potiuk · 4 weeks ago
  32. 5eda682 chore: add branch protection rules by lprimak · 4 weeks ago
  33. 4fb4cbb chore(deps): bump org.apache:apache from 37 to 38 by dependabot[bot] · 4 weeks ago
  34. 5f13983 chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin by dependabot[bot] · 4 weeks ago
  35. 36aa076 chore(deps): bump org.apache.johnzon:johnzon-jsonb from 1.2.22 to 1.3.0 by dependabot[bot] · 4 weeks ago
  36. ebb1d2f chore(deps): bump the github-actions-dependencies group with 3 updates by dependabot[bot] · 4 weeks ago
  37. 7cd0b1c chore(deps): bump slf4j.version from 2.0.17 to 2.0.18 by dependabot[bot] · 4 weeks ago
  38. 0819229 chore: remove extra newline by lprimak · 5 weeks ago
  39. a46600f improvement: implemented session key rotation via changeSessionId() in Web-Container mode only by lprimak · 5 weeks ago
  40. be31c13 enh(jakarta-ee): encrypt SAVED_REQUEST_KEY cookie by lprimak · 5 weeks ago
  41. 97218c0 Merge pull request #2689 from apache/dependabot/github_actions/github-actions-dependencies-937d73b4db by François Papon · 5 weeks ago
  42. d6246a0 Merge pull request #2691 from apache/dependabot/maven/org.apache.karaf.features-framework-4.4.11 by François Papon · 5 weeks ago
  43. 5ab9e46 Merge pull request #2692 from apache/dependabot/maven/org.owasp-dependency-check-maven-12.2.2 by François Papon · 5 weeks ago
  44. 4cb75d9 chore(deps): bump org.owasp:dependency-check-maven from 12.2.1 to 12.2.2 by dependabot[bot] · 5 weeks ago
  45. 05a915f chore(deps): bump org.apache.karaf.features:framework by dependabot[bot] · 5 weeks ago
  46. 0cc8c1a chore(deps): bump github/codeql-action by dependabot[bot] · 5 weeks ago
  47. c95a185 enh: reverted secureInDevMode addition and added native session management secure cookie by lprimak · 6 weeks ago
  48. 2148939 [CI] Add ASF Allowlist Check workflow (#2687) by John Bampton · 6 weeks ago
  49. 80f635c enh(jakarta-ee): added secure configuration for session cookies automatically by lprimak · 6 weeks ago
  50. 8f98ac8 chore(deps): bump https://github.com/oxipng/oxipng (#2676) by dependabot[bot] · 6 weeks ago
  51. 9396183 chore: fixed deprecated methods in Hasher by lprimak · 6 weeks ago
  52. 92eb6fb enh: destroy existing session upon login by lprimak · 6 weeks ago
  53. be89663 enh: rememberMe cookie options by lprimak · 6 weeks ago
  54. ea18c92 chore(deps-dev): bump org.bouncycastle:bcprov-jdk18on from 1.82 to 1.84 (#2662) by dependabot[bot] · 6 weeks ago
  55. 4b2cd7d chore(deps): bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#2672) by dependabot[bot] · 6 weeks ago
  56. 0d83fbd chore(deps): bump org.projectlombok:lombok from 1.18.44 to 1.18.46 (#2675) by dependabot[bot] · 6 weeks ago
  57. 3e4d89e chore(deps): bump org.omnifaces:omnifaces from 3.14.15 to 3.14.20 (#2673) by dependabot[bot] · 6 weeks ago
  58. 0ca5870 chore(deps-dev): bump org.jboss.arquillian.graphene:graphene-webdriver (#2671) by dependabot[bot] · 6 weeks ago
  59. 4abdbb2 chore(deps): bump org.jsoup:jsoup from 1.22.1 to 1.22.2 (#2669) by dependabot[bot] · 6 weeks ago
  60. 11d54cf chore(deps-dev): bump org.javassist:javassist (#2668) by dependabot[bot] · 6 weeks ago
  61. 797ac5f chore(deps): bump the github-actions-dependencies group across 1 directory with 3 updates (#2667) by dependabot[bot] · 6 weeks ago
  62. e20f47f chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin (#2666) by dependabot[bot] · 6 weeks ago
  63. 54dc874 chore(deps): bump https://github.com/zizmorcore/zizmor-pre-commit (#2661) by dependabot[bot] · 6 weeks ago
  64. b52b851 chore(deps): bump org.owasp:dependency-check-maven from 12.2.0 to 12.2.1 (#2660) by dependabot[bot] · 6 weeks ago
  65. 173b1a2 chore(deps): bump org.apache.commons:commons-configuration2 (#2658) by dependabot[bot] · 6 weeks ago
  66. eecdd87 Merge pull request #2656 from apache/dependabot/maven/bytebuddy.version-1.18.8 by Boris Petrov · 9 weeks ago
  67. 08803e3 Merge pull request #2649 from apache/dependabot/pre_commit/pre-commit-hooks-820b35f878 by Boris Petrov · 9 weeks ago
  68. 4d2c66f Merge pull request #2645 from apache/dependabot/maven/org.omnifaces-omnifaces-3.14.15 by Boris Petrov · 9 weeks ago
  69. 82ecd88 Merge pull request #2644 from apache/dependabot/github_actions/github-actions-dependencies-fd00acb19b by Boris Petrov · 9 weeks ago
  70. 109eb23 Merge pull request #2643 from apache/dependabot/maven/log4j.version-2.25.4 by Boris Petrov · 9 weeks ago
  71. 114809c chore(deps): bump bytebuddy.version from 1.18.7 to 1.18.8 by dependabot[bot] · 9 weeks ago
  72. 142ef76 chore(deps): bump https://github.com/rhysd/actionlint by dependabot[bot] · 2 months ago
  73. 6245aef chore(deps): bump org.omnifaces:omnifaces from 3.14.13 to 3.14.15 by dependabot[bot] · 2 months ago
  74. 2446b08 chore(deps): bump github/codeql-action by dependabot[bot] · 2 months ago
  75. 371cbe6 chore(deps): bump log4j.version from 2.25.3 to 2.25.4 by dependabot[bot] · 2 months ago
  76. 7292f16 Merge remote-tracking branch 'upstream/main' by lprimak · 2 months ago
  77. 2ea056f chore(deps): bump the github-actions-dependencies group with 2 updates (#2640) by dependabot[bot] · 2 months ago
  78. e403290 chore(deps): bump org.apache.rat:apache-rat-plugin from 0.17 to 0.18 (#2641) by dependabot[bot] · 2 months ago
  79. f3e897f [CI] Create reusable pre-commit workflows (#2635) by John Bampton · 3 months ago
  80. cbdee2e chore(deps-dev): bump arquillian.core.version (#2637) by dependabot[bot] · 3 months ago
  81. 709b1fb chore(deps): bump github/codeql-action (#2638) by dependabot[bot] · 3 months ago
  82. 5c5a1df Merge remote-tracking branch 'upstream/main' by lprimak · 3 months ago
  83. b88e03c Merge pull request #2634 from lprimak/update-gh-description by François Papon · 3 months ago
  84. d8f978e split line by lprimak · 3 months ago
  85. f28077e enh: update description is GitHub by lprimak · 3 months ago
  86. 2558789 bugfix: logout is not blocked if it's remembered request even if resubmitted by lprimak · 3 months ago
  87. f556a12 bugfix(jakarta-ee): form resubmit: login submit response processing fixed (#2632) by Lenny Primak · 3 months ago
  88. 6a2af15 chore(deps): bump mockito.version from 5.22.0 to 5.23.0 (#2627) by dependabot[bot] · 3 months ago
  89. f5b6a6c chore(deps): bump https://github.com/gitleaks/gitleaks (#2628) by dependabot[bot] · 3 months ago
  90. 74ebad6 Add descriptive labels to dependabot groups (#2626) by John Bampton · 3 months ago
  91. b1eca1d chore: moved tomcat 10 version into a variable by lprimak · 3 months ago
  92. df947f9 chore: moved manual tomcat version to variable by lprimak · 3 months ago
  93. ea4ac9b chore(deps): bump org.omnifaces:omnifaces from 3.14.12 to 3.14.13 (#2612) by dependabot[bot] · 3 months ago
  94. cf2f71e chore(deps): bump org.apache.tomcat:tomcat-catalina (#2615) by dependabot[bot] · 3 months ago
  95. edfa467 chore(deps): bump org.apache.tomcat.embed:tomcat-embed-core (#2618) by dependabot[bot] · 3 months ago
  96. 58b475a chore(deps): bump org.apache.tomcat.embed:tomcat-embed-core (#2619) by dependabot[bot] · 3 months ago
  97. 3f566c6 Merge pull request #2617 from apache/dependabot/maven/samples/spring-boot-web/org.apache.tomcat.embed-tomcat-embed-core-9.0.113 by François Papon · 3 months ago
  98. f4bc9de Merge pull request #2616 from apache/dependabot/maven/integration-tests/meecrowave-support/org.apache.tomcat-tomcat-catalina-9.0.113 by François Papon · 3 months ago
  99. 02b5f8e Merge pull request #2613 from apache/dependabot/maven/org.apache.maven.plugins-maven-resources-plugin-3.5.0 by François Papon · 3 months ago
  100. 4099ab7 Merge pull request #2621 from apache/dependabot/pre_commit/github-dependencies-e573e0e192 by François Papon · 3 months ago