You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@sling.apache.org by ol...@apache.org on 2017/03/08 07:47:22 UTC

svn commit: r18605 - /release/sling/

Author: olli
Date: Wed Mar  8 07:47:21 2017
New Revision: 18605

Log:
XSS 1.0.18

Added:
    release/sling/org.apache.sling.xss-1.0.18-javadoc.jar   (with props)
    release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.asc
    release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.md5
    release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.sha1
    release/sling/org.apache.sling.xss-1.0.18-source-release.zip   (with props)
    release/sling/org.apache.sling.xss-1.0.18-source-release.zip.asc
    release/sling/org.apache.sling.xss-1.0.18-source-release.zip.md5
    release/sling/org.apache.sling.xss-1.0.18-source-release.zip.sha1
    release/sling/org.apache.sling.xss-1.0.18-sources.jar   (with props)
    release/sling/org.apache.sling.xss-1.0.18-sources.jar.asc
    release/sling/org.apache.sling.xss-1.0.18-sources.jar.md5
    release/sling/org.apache.sling.xss-1.0.18-sources.jar.sha1
    release/sling/org.apache.sling.xss-1.0.18.jar   (with props)
    release/sling/org.apache.sling.xss-1.0.18.jar.asc
    release/sling/org.apache.sling.xss-1.0.18.jar.md5
    release/sling/org.apache.sling.xss-1.0.18.jar.sha1
    release/sling/org.apache.sling.xss-1.0.18.pom
    release/sling/org.apache.sling.xss-1.0.18.pom.asc
    release/sling/org.apache.sling.xss-1.0.18.pom.md5
    release/sling/org.apache.sling.xss-1.0.18.pom.sha1
Removed:
    release/sling/org.apache.sling.xss-1.0.16-javadoc.jar
    release/sling/org.apache.sling.xss-1.0.16-javadoc.jar.asc
    release/sling/org.apache.sling.xss-1.0.16-javadoc.jar.md5
    release/sling/org.apache.sling.xss-1.0.16-javadoc.jar.sha1
    release/sling/org.apache.sling.xss-1.0.16-source-release.zip
    release/sling/org.apache.sling.xss-1.0.16-source-release.zip.asc
    release/sling/org.apache.sling.xss-1.0.16-source-release.zip.md5
    release/sling/org.apache.sling.xss-1.0.16-source-release.zip.sha1
    release/sling/org.apache.sling.xss-1.0.16-sources.jar
    release/sling/org.apache.sling.xss-1.0.16-sources.jar.asc
    release/sling/org.apache.sling.xss-1.0.16-sources.jar.md5
    release/sling/org.apache.sling.xss-1.0.16-sources.jar.sha1
    release/sling/org.apache.sling.xss-1.0.16.jar
    release/sling/org.apache.sling.xss-1.0.16.jar.asc
    release/sling/org.apache.sling.xss-1.0.16.jar.md5
    release/sling/org.apache.sling.xss-1.0.16.jar.sha1
    release/sling/org.apache.sling.xss-1.0.16.pom
    release/sling/org.apache.sling.xss-1.0.16.pom.asc
    release/sling/org.apache.sling.xss-1.0.16.pom.md5
    release/sling/org.apache.sling.xss-1.0.16.pom.sha1

Added: release/sling/org.apache.sling.xss-1.0.18-javadoc.jar
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-1.0.18-javadoc.jar
------------------------------------------------------------------------------
    svn:mime-type = application/octet-stream

Added: release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.asc
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.asc (added)
+++ release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.asc Wed Mar  8 07:47:21 2017
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIcBAABCgAGBQJYuS+qAAoJEDo/m6YOSwgmCv8P/jASONZonO+xtq9S3NWfp6Oj
+i44NkyBL/WfE0eHED9RIO2fDOnvu6MZ6+fXdP9eY3I4i/BgKA/m3jyYvZOzyHZ8w
+pRMjijj5ygavTPbZhQx1kzPRgul1sSUMOywc3H5spHXwgOksuxWz8q7iARoQaIdD
+n5+AOKKtuMy+XbkO38T1G0S5AlJ9zV9G+9u9B/KXzJHUJt6paH4OBnH+kmhN79Pv
+IHJS0e3JqkH4VfueIUaPyVkPznaPz0wVpq3qjv6qR4Ad+6OVCanU1RFs0xQsp8sp
+yxvNkwPqw8Fbq0owHqJP0rY7pjbeseWCWYCvp1jAE+JFNzG2rX3pbgQfbBO4jUVK
+RnlAG8jW96r69013kxaW0Un/OAIP+l/56niwjv4TmZjPaOnWPQsfSxpfM5UGL84q
+2UbmIOYUyToMUK7CdGISSR99MTwUZZZnDKlCjVHjgITmDYXCLPabLFEQj/H/cZn/
+uq5IkZyFo9Pe5JcRcki7n4d6Ch2hguMeblFj6vrgwRS6CSlfSAU6QboOmwr0R4V+
+XOJadyw0YQXB2Rt5el10MeWv7TxmC+D5qePu/t8WNkEGtZ4ZgnCt0uNup+8gM0sm
+tcPVZL77cquAVsKm7T6+YOvEk3aLxD2DHd7Nke6CuColyju4TPOy/33xF9/xUKQV
+B1haU6WS5NCW1kVrf8GW
+=FCYE
+-----END PGP SIGNATURE-----

Added: release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.md5
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.md5 (added)
+++ release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.md5 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+e2d9087b0fa265618e45fb1cecb3e9b9
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.sha1 (added)
+++ release/sling/org.apache.sling.xss-1.0.18-javadoc.jar.sha1 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+07884d5d38c039d52186a433353152ef2c801afe
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18-source-release.zip
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-1.0.18-source-release.zip
------------------------------------------------------------------------------
    svn:mime-type = application/octet-stream

Added: release/sling/org.apache.sling.xss-1.0.18-source-release.zip.asc
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-source-release.zip.asc (added)
+++ release/sling/org.apache.sling.xss-1.0.18-source-release.zip.asc Wed Mar  8 07:47:21 2017
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIcBAABCgAGBQJYuS+qAAoJEDo/m6YOSwgmw7AP/i1oBib/89i5MTglUXSnECrN
+wAuUGvjylhgevnIH3Pifkidfvn+qvTcZ/Amc+nu/9GDj1Qqp92QUZH9kgDpi7Fbc
+Jo/jOQhsY+WbuPASIkNPqwgOpewgRv4hVJImTvSLSNju99DR9f+PLZ60Z9JpeKLe
+7gOkv9tQkGAUZlUQg4rm4QGgXMAJCvnanZ4j9nU9kbGgnSInbnGw9leSBwN4W9hP
+kZOiMuhpLR3XditaiOgjdumn2ZMDI6DRdUJYawI3DjPMGpcOnaNteD7DSdQ0hT8J
+F+xAiweCHkmsXvMbSZ/3AgrJog6+/JgsktCHHTDNi3/U/IsFXROb6SZE+Q3gi84E
+Ok+s9X7CrFJkbQ5oThbH//1aypXf9zPH8N68w4CiaDnj6VM2JWDKMeQ39oueUCU9
+Rjuj6pilCfzE5Uvgo3zhkJrhbiOjCZSowZFmOGjyM0fUf8gfakUJfWaDNuTkPrYT
+jqw2YCRaTOQyIKZMU3+QhWtLy6V++u0IrUgELB4KtidvdylnEaX7mn7mhwxafg9G
+vdxLW4AmPffVfpOnXiH0ORqEDNL1FOGTeLcLyZOqwzf3zGpbeAHCvZ8qcDnlgs6v
+KEqunWufp/vtgPvHR4N0qMGiuL+Drkt3eYc7WZGpBbZ5QVP5XrvmbWwgYzZMnpvZ
+r9YAK/sWLrozr8SxgqlT
+=7ZIZ
+-----END PGP SIGNATURE-----

Added: release/sling/org.apache.sling.xss-1.0.18-source-release.zip.md5
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-source-release.zip.md5 (added)
+++ release/sling/org.apache.sling.xss-1.0.18-source-release.zip.md5 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+5a9057188a4aafa377d237a66835c63a
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18-source-release.zip.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-source-release.zip.sha1 (added)
+++ release/sling/org.apache.sling.xss-1.0.18-source-release.zip.sha1 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+455a5133736d1918a7b1c1f2f82c599019109004
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18-sources.jar
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-1.0.18-sources.jar
------------------------------------------------------------------------------
    svn:mime-type = application/octet-stream

Added: release/sling/org.apache.sling.xss-1.0.18-sources.jar.asc
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-sources.jar.asc (added)
+++ release/sling/org.apache.sling.xss-1.0.18-sources.jar.asc Wed Mar  8 07:47:21 2017
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIcBAABCgAGBQJYuS+qAAoJEDo/m6YOSwgmc9oQAK6rATpH0X8gY+Q67GVNnkC9
+uzBGxjrqYIdeSkvJv3sHgtXIRWMbp/OH2EfyFg0jLZbyEmiomFOtOYwSOW5/F2H7
+Lxi6pBkvJikkYM+Ui4/NGUluKCiects2MZ6cdt24NFNdvKykNa8ERk0U66OcCWnX
+oeZl9JvH63j+4xWOmj9iJCh+3cqES8izD6tebDbnA+KRvnT3Dn3bOpV4AwRzMTpo
+V7efxxWn04XtQeTD3fKzPJDRtHUiRtACEX7wmNXiN9Hmc51UhlRKae9+GWlidiP0
+RiJ6wq0SD7KuKEgitnmhFNd8+yWVZVvUwTGDJWXEvo2C/C9TnXwZrRGMhyQ3tcU+
+txfV7nFrH/0KCSj1gTn6FS9MrWvCHTkOmMeWT+MolRid/lejgwsxC7eqr4xi37PA
+5bdp6urKG/zKZqLEtBlCGYKuOqxkEMiEa6zayzLtwSpnFqRU6KtYfLNuclK5QkWk
+oB60COdIbraWeVDUbt5Ao91GIQnH7nf7BWBCd5MWKauPvWY+C3lP1m/yCi4Z8keU
+MnLw6gMK3WdOgau92/iFIEKOk4OUOoq1QxFmsRFSmAX9lqRRBYmPBIzltNq+wF0+
+Vgg49Mqn/S6LxIZRaxa+jwc3pO0G1giIARg3iQJEW5MbWlC25ACNacpISjbHM8Wx
+PLwNETMlSH6cWelhCL/W
+=FDC/
+-----END PGP SIGNATURE-----

Added: release/sling/org.apache.sling.xss-1.0.18-sources.jar.md5
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-sources.jar.md5 (added)
+++ release/sling/org.apache.sling.xss-1.0.18-sources.jar.md5 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+7d407293a26151e4a1f219f8bdf2f0c9
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18-sources.jar.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18-sources.jar.sha1 (added)
+++ release/sling/org.apache.sling.xss-1.0.18-sources.jar.sha1 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+b8d925844392858e6f9756a1194459aefb3621fa
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18.jar
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-1.0.18.jar
------------------------------------------------------------------------------
    svn:mime-type = application/octet-stream

Added: release/sling/org.apache.sling.xss-1.0.18.jar.asc
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18.jar.asc (added)
+++ release/sling/org.apache.sling.xss-1.0.18.jar.asc Wed Mar  8 07:47:21 2017
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIcBAABCgAGBQJYuS+qAAoJEDo/m6YOSwgmuBQP+wTUaaDzqlTcKklilQkNj7hO
+ZXGWBo9VbkhIU8l3knfyx7MXjj8ViTCvGiOxoi98FpX6UHqcYfO60+DO3orejxeL
+GIgGsi7igAMGYlPNg0jFTCb9sXX5pHiPAMzHe/O27FoyqLPIItiaYO69PT4VWSyz
+PD+qWR7+HTt2UJHadGOaeEyud4pDS1pZyE1/jZXVlg6aQfZv0A7Pwi8KlABOYqLJ
+pt2S9+6LXt1e2lbO/H5EjkvWm4vukCcvQ3kH9+7+dAq/6+I43+LJ/mVQZbzQYZT7
+5MIGbbPemEk9ewzshYMdMeynSxh4kk0Im721dN9HeVie+xpAU3fk9DXweB4ve/vW
+rLythElf58adPBgD1l3bOmHZwB7cx6weWH1z/CQcQ4zwjM9rjELzqzg3sRxREj3a
+1RAH5DmE3O1r4FtFrJ+74T7MVZTqizmw1i/X4jbnZTcQ/UzTbg+Fu9z/ZXDmmPXG
+SgMHQVMbzoBDrLE64CJ/s0ZKsTfZI6aqKqh7Y7WzCKilHjkwMrIOld0RFj16WGYN
++SGq2Drpw9qfWbzQt3CyiOYeMhn+BJnlGx2xIJX53Ey19bo0jcK+dJJwZCWWD9Ex
+sZNHi2kg6CKNn+D3CGV6i7FSnnFyoqm6CHEpJZd9+yPcXLPK+UoZ2yR1ONXUJNw2
+PkitV3U4c59Q2Ti9BmFU
+=km9N
+-----END PGP SIGNATURE-----

Added: release/sling/org.apache.sling.xss-1.0.18.jar.md5
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18.jar.md5 (added)
+++ release/sling/org.apache.sling.xss-1.0.18.jar.md5 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+fca54dcf3d812587051f936e4d10871a
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18.jar.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18.jar.sha1 (added)
+++ release/sling/org.apache.sling.xss-1.0.18.jar.sha1 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+8e970a2580c46f2be7264122f1efda2f0d4f08ca
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18.pom
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18.pom (added)
+++ release/sling/org.apache.sling.xss-1.0.18.pom Wed Mar  8 07:47:21 2017
@@ -0,0 +1,297 @@
+<?xml version="1.0"?>
+<!--~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+  ~ Licensed to the Apache Software Foundation (ASF) under one or
+  ~ more contributor license agreements. See the NOTICE file
+  ~ distributed with this work for additional information regarding
+  ~ copyright ownership. The ASF licenses this file to you under the
+  ~ Apache License, Version 2.0 (the "License"); you may not use
+  ~ this file except in compliance with the License. You may obtain
+  ~ a copy of the License at
+  ~
+  ~ http://www.apache.org/licenses/LICENSE-2.0 Unless required by
+  ~ applicable law or agreed to in writing, software distributed
+  ~ under the License is distributed on an "AS IS" BASIS, WITHOUT
+  ~ WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+  ~ See the License for the specific language governing permissions
+  ~ and limitations under the License.
+  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~-->
+<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
+    <modelVersion>4.0.0</modelVersion>
+    <!-- ======================================================================= -->
+    <!-- P A R E N T   P R O J E C T                                             -->
+    <!-- ======================================================================= -->
+    <parent>
+        <groupId>org.apache.sling</groupId>
+        <artifactId>sling</artifactId>
+        <version>28</version>
+        <relativePath />
+    </parent>
+
+    <!-- ======================================================================= -->
+    <!-- P R O J E C T                                                           -->
+    <!-- ======================================================================= -->
+    <artifactId>org.apache.sling.xss</artifactId>
+    <packaging>bundle</packaging>
+    <version>1.0.18</version>
+
+    <name>Apache Sling XSS Protection Bundle</name>
+    <description>
+        Apache Sling XSS Protection Bundle providing XSS protection based on the OWASP AntiSamy and OWASP Java Encoder libraries.
+    </description>
+
+    <scm>
+        <connection>scm:svn:http://svn.apache.org/repos/asf/sling/tags/org.apache.sling.xss-1.0.18</connection>
+        <developerConnection>scm:svn:https://svn.apache.org/repos/asf/sling/tags/org.apache.sling.xss-1.0.18</developerConnection>
+        <url>http://svn.apache.org/viewvc/sling/tags/org.apache.sling.xss-1.0.18</url>
+    </scm>
+
+
+    <!-- ======================================================================= -->
+    <!-- B U I L D                                                               -->
+    <!-- ======================================================================= -->
+    <build>
+        <pluginManagement>
+            <plugins>
+                <plugin>
+                    <!-- Extend RAT configuration from parent pom -->
+                    <groupId>org.apache.rat</groupId>
+                    <artifactId>apache-rat-plugin</artifactId>
+                    <configuration>
+                        <excludes combine.children="append">
+                            <exclude>src/main/resources/ESAPI.properties</exclude>
+                            <exclude>src/main/resources/validation.properties</exclude>
+                        </excludes>
+                    </configuration>
+                </plugin>
+            </plugins>
+        </pluginManagement>
+
+        <plugins>
+            <plugin>
+                <groupId>org.apache.felix</groupId>
+                <artifactId>maven-scr-plugin</artifactId>
+            </plugin>
+            <plugin>
+                <groupId>org.apache.sling</groupId>
+                <artifactId>maven-sling-plugin</artifactId>
+            </plugin>
+            <plugin>
+                <groupId>org.apache.felix</groupId>
+                <artifactId>maven-bundle-plugin</artifactId>
+                <extensions>true</extensions>
+                <configuration>
+                    <instructions>
+                        <Import-Package>
+                            !bsh,
+                            !nu.xom,
+                            !org.apache.log4j.spi,
+                            !org.apache.log4j.xml,
+                            !org.w3c.dom.svg,
+                            !org.apache.avalon.framework.logger,
+                            !org.apache.commons.jxpath.*,
+                            !org.apache.commons.digester.*,
+                            !org.apache.tools.ant.taskdefs,
+                            !org.apache.xml.resolver,
+                            !org.apache.xml.resolver.readers,
+                            !org.apache.log,
+                            !sun.io,
+                            *
+                        </Import-Package>
+                        <Private-Package>
+                            org.apache.sling.xss.impl,
+                            org.apache.batik.*,
+                            org.w3c.css.sac,
+                            org.apache.xerces.*,
+                            org.apache.xml.serialize,
+                            org.apache.commons.beanutils.*;-split-package:=merge-first,
+                            org.apache.commons.configuration.*,
+                            org.apache.commons.logging.impl,
+                            org.cyberneko.html.*,
+                        </Private-Package>
+                        <Embed-Dependency>
+                            antisamy;inline=true,
+                            esapi;inline=true,
+                            encoder;inline=true
+                        </Embed-Dependency>
+                        <Sling-Initial-Content>
+                            SLING-INF/content;path:=/libs/sling/xss;overwrite:=true;ignoreImportProviders:=xml
+                        </Sling-Initial-Content>
+                    </instructions>
+                </configuration>
+            </plugin>
+        </plugins>
+    </build>
+
+    <!-- ======================================================================= -->
+    <!-- D E P E N D E N C I E S                                                 -->
+    <!-- ======================================================================= -->
+    <dependencies>
+        <dependency>
+            <groupId>org.owasp.antisamy</groupId>
+            <artifactId>antisamy</artifactId>
+            <version>1.5.2</version>
+            <scope>provided</scope>
+            <exclusions>
+                <exclusion>
+                    <groupId>nu.xom</groupId>
+                    <artifactId>com.springsource.nu.xom</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>bsh</groupId>
+                    <artifactId>bsh</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.axsl.org.w3c.dom.svg</groupId>
+                    <artifactId>svg-dom-java</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>commons-jxpath</groupId>
+                    <artifactId>commons-jxpath</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.apache.commons</groupId>
+                    <artifactId>commons-digester3</artifactId>
+                </exclusion>
+                <!-- #40108 - XSS protection does not work on Java 5 -->
+                <!-- Replace batik-css 1.7 with 1.6. See below.      -->
+                <exclusion>
+                    <groupId>org.apache.xmlgraphics</groupId>
+                    <artifactId>batik-css</artifactId>
+                </exclusion>
+            </exclusions>
+        </dependency>
+        <!-- <#40108 - XSS protection does not work on Java 5>  -->
+        <!-- Replace batik-css 1.7 with 1.6 to avoid breaking   -->
+        <!-- the build on Java 5. The batik-css 1.6 pom doesn't -->
+        <!-- have proper dependency metadata, so we need to     -->
+        <!-- reconstruct the full list here.                    -->
+        <!-- TODO: Remove this workaround when we dump Java 5.  -->
+        <dependency>
+            <groupId>batik</groupId>
+            <artifactId>batik-css</artifactId>
+            <version>1.6</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>batik</groupId>
+            <artifactId>batik-ext</artifactId>
+            <version>1.6</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>batik</groupId>
+            <artifactId>batik-util</artifactId>
+            <version>1.6</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>batik</groupId>
+            <artifactId>batik-gui-util</artifactId>
+            <version>1.6</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>xml-apis</groupId>
+            <artifactId>xml-apis-ext</artifactId>
+            <version>1.3.04</version>
+            <scope>provided</scope>
+        </dependency>
+        <!-- </#40108 - XSS protection does not work on Java 5> -->
+
+        <dependency>
+            <groupId>org.owasp.esapi</groupId>
+            <artifactId>esapi</artifactId>
+            <version>2.1.0</version>
+            <scope>provided</scope>
+            <exclusions>
+                <exclusion>
+                    <groupId>nu.xom</groupId>
+                    <artifactId>com.springsource.nu.xom</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>bsh</groupId>
+                    <artifactId>bsh</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.axsl.org.w3c.dom.svg</groupId>
+                    <artifactId>svg-dom-java</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>commons-jxpath</groupId>
+                    <artifactId>commons-jxpath</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.apache.commons</groupId>
+                    <artifactId>commons-digester3</artifactId>
+                </exclusion>
+            </exclusions>
+        </dependency>
+
+        <dependency>
+            <groupId>org.owasp.encoder</groupId>
+            <artifactId>encoder</artifactId>
+            <scope>provided</scope>
+            <version>1.1.1</version>
+        </dependency>
+
+        <dependency>
+            <groupId>javax.servlet</groupId>
+            <artifactId>javax.servlet-api</artifactId>
+            <scope>provided</scope>
+        </dependency>
+
+        <dependency>
+            <groupId>org.osgi</groupId>
+            <artifactId>osgi.core</artifactId>
+        </dependency>
+        <dependency>
+            <groupId>org.slf4j</groupId>
+            <artifactId>slf4j-api</artifactId>
+        </dependency>
+        <dependency>
+            <groupId>org.apache.sling</groupId>
+            <artifactId>org.apache.sling.api</artifactId>
+            <version>2.11.0</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.apache.sling</groupId>
+            <artifactId>org.apache.sling.commons.json</artifactId>
+            <version>2.0.6</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+          <groupId>org.apache.sling</groupId>
+          <artifactId>org.apache.sling.serviceusermapper</artifactId>
+          <version>1.2.0</version>
+          <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>com.google.code.findbugs</groupId>
+            <artifactId>jsr305</artifactId>
+            <version>2.0.0</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>junit</groupId>
+            <artifactId>junit</artifactId>
+        </dependency>
+        <dependency>
+            <groupId>org.mockito</groupId>
+            <artifactId>mockito-all</artifactId>
+            <version>1.10.19</version>
+            <scope>test</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.powermock</groupId>
+            <artifactId>powermock-api-mockito</artifactId>
+            <version>1.6.5</version>
+            <scope>test</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.slf4j</groupId>
+            <artifactId>slf4j-simple</artifactId>
+        </dependency>
+    </dependencies>
+
+</project>

Added: release/sling/org.apache.sling.xss-1.0.18.pom.asc
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18.pom.asc (added)
+++ release/sling/org.apache.sling.xss-1.0.18.pom.asc Wed Mar  8 07:47:21 2017
@@ -0,0 +1,16 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQIcBAABCgAGBQJYuS+qAAoJEDo/m6YOSwgmIGgQAK2dhbV28IXkrTAZBEZSXZDu
+0pvrvrV87KRH3qxZ06U9EE32gY0f8KjkLklFUmifyRbLaXkCqeX697YhrYWJ3DaC
+3UY3B21u2PItzdT1JTfadYGtribRa3ubdBo2Tg8ieLQSTbh6w/ibdMiRkFdlL53f
+RLaVB6KGpVZhobtKOYowH7X6AZY3i+Em+jWifJx1vk/LXsbiQlR9j3utCwmTOJCn
+MvbAcb8c+o8n9p+dcm7ODLcCcD1Hcrv5TBaCvbvdC4iZYIEZ53A//KZp8uwfQolb
+1im6YYxfpkD3oFWQD77JiUcSXUmeLQqhl8i8brcDwiKAkAhT0uDqfLwGiVMuROSg
+9MF5zWchmP0mTSxDXyRQ6Io+SXwopZcNJWW4KDAE4IrDLtSardZGuTwcwjkYCAuq
+0XqpPXihLelqDRdln3H0uF1LN3EnsE822iOIqJk20NrAzg0FfxqxfGxp0DIc+8/B
+mE6FEH9w5z7iCf3+DupHU34/gK/jMjvNgcfchFeAh01NNFUsVruE8Q97UBRYL3dQ
+eLwB2uadsRkTN4FBrPvfI17ydBlBWYtUMXtVo/2a+6wt4OhvFoO+Tr4cjPwKMuK9
+RjaVPK9gKMoR7a83fUpU/7H19JrTdV5ZjG8hxEB9R5p3LCHRFacc3jjwZGtvKuvW
+LdDgXjA1m0nFy41+0A2V
+=/5oJ
+-----END PGP SIGNATURE-----

Added: release/sling/org.apache.sling.xss-1.0.18.pom.md5
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18.pom.md5 (added)
+++ release/sling/org.apache.sling.xss-1.0.18.pom.md5 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+f50866d028090393fdeec6b0b39cd4ec
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-1.0.18.pom.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-1.0.18.pom.sha1 (added)
+++ release/sling/org.apache.sling.xss-1.0.18.pom.sha1 Wed Mar  8 07:47:21 2017
@@ -0,0 +1 @@
+bbc59b7ce63c6fe6636c92dde031e3cdedf4a4a0
\ No newline at end of file