Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-17599

Upgrade to CSS4J 2.0.5

    XMLWordPrintable

Details

    • Task
    • Resolution: Duplicate
    • Major
    • None
    • 12.6
    • Dependency Upgrades
    • None
    • Unit
    • Unknown
    • N/A
    • N/A

    Description

      CSS4J CHANGES
      =============
      
      Version 2.0.5
      -------------
      
       * Core:
      - NSAC impl.: protect against Billion Laughs Attack in var() values.
      - CSSOM: use the Denial of Service prevention introduced in [02da0213].
      - CSSOM: if a lexical value contained many var() references, some could be left 
        unreplaced.
      - CSSOM: add a public setLexicalUnit(LexicalUnit) method to LexicalValue.
      - CSSOM: clone() some lexical values before operating on them.
      - CSSOM: some corner cases of custom properties being used to set shorthands 
        did not work.
      - PropertyDatabase: add a few level 4 font properties.
      - Tests: add a test for Billion Laughs Attack on var() values.
      - Maven POM: make sure that javadocs are built with JDK 14.
      - Maven POM: produce a package-list with javadoc-packagelist-maven-plugin.
      - Maven POM: general cleanup.
      
       * Dom4j module:
      - Maven POM: make sure that javadocs are built with JDK 14.
      - Maven POM: general clean-up.
      
       * Agent module:
      - Maven POM: make sure that javadocs are built with JDK 14.
      - Maven POM: general clean-up.
      
       * AWT module:
      - Maven POM: general clean-up.
      

      Attachments

        Activity

          People

            vmassol Vincent Massol
            vmassol Vincent Massol
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: