efegokdemir opened a new pull request, #803:
URL: https://github.com/apache/maven-indexer/pull/803

   ## Summary
   
   `MavenPluginArtifactInfoIndexCreator` currently wraps `plugin.xml` in an 
`InputStreamReader` without an explicit charset, so descriptors are decoded 
using the host platform's default encoding. This can corrupt non-UTF-8 
descriptors and their indexed plugin metadata.
   
   This change uses the JDK StAX parser so the XML declaration controls 
decoding, while retaining the existing prefix and goal extraction.
   
   ## Changes
   
   - Replace the `Xpp3Dom` descriptor reader with the JDK XML stream reader.
   - Disable DTD and external entity processing for descriptor parsing.
   - Add a regression test for an ISO-8859-1 descriptor containing non-ASCII 
prefix and goal values.
   
   ## Testing
   
   - `JAVA_HOME=/opt/homebrew/opt/openjdk@21 mvn -pl indexer-core -DskipITs 
-Dtest=MavenPluginArtifactInfoIndexCreatorTest test`
   - `JAVA_HOME=/opt/homebrew/opt/openjdk@21 mvn -pl indexer-core -DskipITs 
verify`
   - `JAVA_HOME=/opt/homebrew/opt/openjdk@21 mvn -Prun-its verify`
   - `git diff --check`
   
   All completed successfully. The `run-its` profile is not defined in the 
current POM; Maven emitted a profile warning and the reactor still completed 
its integration tests successfully.
   
   Fixes #798
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to