Hello Claude,

Looks fine on XWiki side.

We get new warnings because of velocimacro.enable_bc_mode=true being
deprecated (it can hardly be removed without breaking a lot of existing
stuff, unfortunately), but that's another story. We'll
use runtime.deprecation.warn for now, and we'll need to try to allocate
some time on finding a proper migration path...

On Fri, Sep 25, 2026 at 6:53 PM Claude Brisson via dev <
[email protected]> wrote:

> The test build of Velocity Engine 2.5 RC2 is available.
>
> No determination as to the quality ('alpha,' 'beta,' or 'GA') of
> Velocity Engine 2.5 has been made, and at this time it is simply a "test
> build". We welcome any comments you may have, and will take all feedback
> into account if a quality vote is called for this build.
>
> Release notes:
>
> *
>
> https://dist.apache.org/repos/dist/dev/velocity/velocity-engine/2.5/release-notes.html
>
> Distribution:
>
>   * https://dist.apache.org/repos/dist/dev/velocity/velocity-engine/2.5/
>
> Maven 2 staging repository:
>
>   *
> https://repository.apache.org/content/repositories/orgapachevelocity-1052/
>
> Documentation:
>
> * https://velocity.apache.org/engine/2.5/
>
> Sources:
>
>   * https://github.com/apache/velocity-engine/releases/tag/2.5-RC2
>
> Changes since RC1:
>
> - No longer deprecated: informal navigation $foo.bar, the ${foo|alt}
> alternate value, and the extra dollar in ${$foo}.
> - Deprecation warnings are now on by default (runtime.deprecation.warn =
> true).
> - New deprecations:
>      - a backslash right before the closing quote of a double-quoted
> string, as in "foo\"
>      - lenient math (runtime.strict_math = false, still the default, so
> it warns at startup)
>      - velocimacro.enable_bc_mode = true
>      - the old default macro library name VM_global_library.vm
>      - runtime.immutable_ranges = false
>      - RuntimeServices.createNewParser()
>      - parser.class and customizing the $ character in a custom parser
> - Security hardening:
>      - #evaluate honors the directive.parse.max_depth nesting limit
>      - resource names are normalized, and loaders refuse names climbing
> above their root
>      - SecureUberspector checks class objects before looking up static
> methods
> - VELOCITY-999: SecureUberspector now uses the configured type
> conversion handler
> - VELOCITY-1000: invalidSetMethod() now receives the whole assigned
> reference, not just its root
>
> A vote regarding the quality of this test build will be initiated within
> the next couple of days.
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

-- 
Thomas Mortagne

Reply via email to