The GitHub Actions job "Java CI" on 
commons-xml.git/docs/supported-runtime-floor has succeeded.
Run started by GitHub user ppkarwasz (triggered by ppkarwasz).

Head commit for run:
27d80d8eeb4d80896feb90354c905be93b5369ee / Piotr P. Karwasz 
<[email protected]>
docs: take Android out of the threat model's guarantee scope

No version of Android supports FEATURE_SECURE_PROCESSING (Android's own
DocumentBuilderFactory.setFeature documentation says so explicitly), so the
guarantees cannot be defined there at all, on any API level:

- threat model: the guarantees are defined on the OpenJDK family only; Android
  moves from an API-33 floor to out of scope on every API level, with a new
  OUT-OF-SCOPE: unsupported runtime triage disposition. The in-scope recipe
  list marks the Expat/KXmlParser recipes as best-effort.
- index: Android remains a supported platform from API level 19, secured as
  best-effort through the resolver floor; the hardening is tested as complete
  starting with API level 33, and below that libexpat carries no
  entity-expansion check. Android's XmlPullParser API is not supported, being
  no JAXP API; parse untrusted XML through the hardened SAX or DOM factories.
- XmlFactories javadoc: the guarantee paragraph now matches.

Assisted-By: Claude Fable 5 <[email protected]>

Report URL: https://github.com/apache/commons-xml/actions/runs/32238159133

With regards,
GitHub Actions via GitBox

Reply via email to