From 4f6f2e7f2263c5974809c8d9a87e6175f3d08cf1 Mon Sep 17 00:00:00 2001 From: kwwall Date: Fri, 17 Jul 2020 21:50:54 -0400 Subject: [PATCH 1/3] Rewrite this as it hadn't been touched for 6+ years. --- README.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 97d49e9..3ad453b 100644 --- a/README.md +++ b/README.md @@ -7,7 +7,8 @@ Welcome to the Home of ESAPI 3.x News ========== -2 Sept 2014 - We are gearing up to get some great stuff done at AppSecUSA in Denver this month. We'll be announcing our schedule and where we'll be at the conference soon! Stay tuned! +The development of ESAPI 3 is still within the _very early_ planning stages. The code that is currently in this GitHub repo (as of 2020-07-17) is likely to be completely rewritten, possibly several times. If you wish to participate, please sign up for the Google Group "[esapi-project-dev](mailto:esapi-project-dev@owasp.org)", and feel free to start a new discussion thread. Note you MUST subscribe to the Google Group list before you may POST to it. [Subscribe to ESAPI Developers list](https://groups.google.com/a/owasp.org/forum/#!forum/esapi-project-dev/join). - -For more information on ESAPI or information on ESAPI 2.x please visit our wiki page at https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API +Notes +========== +For more information on ESAPI or information on ESAPI 2.x please visit our wiki page at https://owasp.org/www-project-enterprise-security-api/ and before you start using ESAPI, do yourself a favor and be sure to read the "[Should I use ESAPI?](https://owasp.org/www-project-enterprise-security-api/#div-shouldiuseesapi)" tab there. From c0fe4b917109c6167e9b096ca60be689b913d7f2 Mon Sep 17 00:00:00 2001 From: "Kevin W. Wall" Date: Thu, 27 Jan 2022 09:43:14 -0500 Subject: [PATCH 2/3] Update README.md Try to clarify that they are probably really looking for ESAPI 2.x at https://github.com/ESAPI/esapi-java-legacy. --- README.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 3ad453b..fde322a 100644 --- a/README.md +++ b/README.md @@ -7,7 +7,10 @@ Welcome to the Home of ESAPI 3.x News ========== -The development of ESAPI 3 is still within the _very early_ planning stages. The code that is currently in this GitHub repo (as of 2020-07-17) is likely to be completely rewritten, possibly several times. If you wish to participate, please sign up for the Google Group "[esapi-project-dev](mailto:esapi-project-dev@owasp.org)", and feel free to start a new discussion thread. Note you MUST subscribe to the Google Group list before you may POST to it. [Subscribe to ESAPI Developers list](https://groups.google.com/a/owasp.org/forum/#!forum/esapi-project-dev/join). +First off, if you are looking for a version of ESAPI to use with your JVM-based project, this is not the one you are looking for. Instead, you want the latest ESAPI 2.x version from [esapi-java-legacy](https://github.com/ESAPI/esapi-java-legacy). This ESAPI repo is for the development of ESAPI 3 which +is still in the _very early_ planning stages. The code that is currently in this GitHub repo (as of 2020-07-17) is likely to be completely rewritten, possibly several times, therefore please do not bother to submit PRs or GitHub issues relating to outdated or vulnerable dependencies. ESAPI 3 has not been released, even as a Release Candidate and we will make sure all the dependencies are updated when we do get around to making RC versions available. + +If you wish to participate, please sign up for the Google Group "[esapi-project-dev](mailto:esapi-project-dev@owasp.org)", and feel free to start a new discussion thread. Note you MUST subscribe to the Google Group list before you may POST to it. [Subscribe to ESAPI Developers list](https://groups.google.com/a/owasp.org/forum/#!forum/esapi-project-dev/join). Notes ========== From 61e4693355bf1b90a29d27149c0ab6436056ab90 Mon Sep 17 00:00:00 2001 From: kwwall Date: Tue, 20 Dec 2022 22:39:57 -0500 Subject: [PATCH 3/3] Update to testng 7.7.0 so dependabot stops complaing about vulnerabilities. (See https://github.com/ESAPI/esapi-java/security/dependabot/1.) Note I think this version of testng requires Java 11 or later. Also note that this really wasn't an issue because: * The vulnerability is only with a dependency of scope 'test'. * We currently have no tests anyway. --- pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index 0655b75..3b87637 100644 --- a/pom.xml +++ b/pom.xml @@ -147,7 +147,7 @@ org.testng testng - 6.8.5 + 7.7.0 test @@ -158,4 +158,4 @@ - \ No newline at end of file +