<?xml version="1.0" encoding="UTF-8"?>
<!--
~ Copyright (c) 2015 OWASP.
~ All rights reserved.
~
~ Redistribution and use in source and binary forms, with or without
~ modification, are permitted provided that the following conditions
~ are met:
~
~     * Redistributions of source code must retain the above
~       copyright notice, this list of conditions and the following
~       disclaimer.
~
~     * Redistributions in binary form must reproduce the above
~       copyright notice, this list of conditions and the following
~       disclaimer in the documentation and/or other materials
~       provided with the distribution.
~
~     * Neither the name of the OWASP nor the names of its
~       contributors may be used to endorse or promote products
~       derived from this software without specific prior written
~       permission.
~
~ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
~ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
~ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
~ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
~ COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
~ INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
~ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
~ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
~ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
~ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
~ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
~ OF THE POSSIBILITY OF SUCH DAMAGE.
-->

<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
    <modelVersion>4.0.0</modelVersion>

    <groupId>org.owasp.encoder</groupId>
    <artifactId>encoder-parent</artifactId>
    <version>1.5.0</version>
    <packaging>pom</packaging>

    <name>OWASP Java Encoder Project</name>
    <description>
        Contextual output encoding for Java 8 and later. The core has no runtime
        dependencies; optional JSP and Jakarta adapters provide view-layer bindings.
        Select an encoder for the destination parser context.
    </description>

    <modules>
        <module>core</module>
        <module>jsp</module>
        <module>jakarta</module>
    </modules>

    <url>https://owasp.org/projects/java-encoder</url>
    <inceptionYear>2011</inceptionYear>
    <organization>
        <name>OWASP Foundation</name>
        <url>https://owasp.org/</url>
    </organization>

    <licenses>
        <license>
            <name>The BSD 3-Clause License</name>
            <url>https://opensource.org/license/bsd-3-clause</url>
            <distribution>repo</distribution>
        </license>
    </licenses>

    <scm child.scm.connection.inherit.append.path="false"
         child.scm.developerConnection.inherit.append.path="false"
         child.scm.url.inherit.append.path="false">
        <developerConnection>scm:git:git@github.com:OWASP/owasp-java-encoder.git</developerConnection>
        <connection>scm:git:https://github.com/OWASP/owasp-java-encoder.git</connection>
        <url>https://github.com/OWASP/owasp-java-encoder</url>
        <tag>v1.5.0</tag>
    </scm>

    <issueManagement>
        <system>github</system>
        <url>https://github.com/OWASP/owasp-java-encoder/issues</url>
    </issueManagement>

    <developers>
        <developer>
            <id>jmanico</id>
            <name>Jim Manico</name>
            <email>jim@owasp.org</email>
            <url>https://github.com/jmanico</url>
            <organization>OWASP Foundation</organization>
            <organizationUrl>https://owasp.org/</organizationUrl>
            <roles><role>Project Leader</role><role>Maintainer</role></roles>
        </developer>
        <developer>
            <id>jeremylong</id>
            <name>Jeremy Long</name>
            <email>jeremy.long@owasp.org</email>
            <url>https://github.com/jeremylong</url>
            <organization>OWASP Foundation</organization>
            <organizationUrl>https://owasp.org/</organizationUrl>
            <roles><role>Project Leader</role><role>Maintainer</role></roles>
        </developer>
    </developers>
    <contributors>
        <contributor>
            <name>Jeff Ichnowski</name>
            <roles><role>Original Author</role><role>Architect</role><role>Developer</role></roles>
        </contributor>
    </contributors>

    <properties>
        <!-- Exact UTC timestamp of the reviewed release-source commit; not build wall-clock time. -->
        <project.build.outputTimestamp>2026-09-28T13:21:37Z</project.build.outputTimestamp>
        <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
        <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
        <!-- Most recent immutable release strictly older than this project version;
             scripts/tests/test_release_baselines.py checks reachable release tags. -->
        <public.api.baseline.version>1.4.1</public.api.baseline.version>
        <japicmp.old.classpath>${settings.localRepository}/org/owasp/encoder/${project.artifactId}/${public.api.baseline.version}/${project.artifactId}-${public.api.baseline.version}.jar</japicmp.old.classpath>
        <japicmp.new.classpath>${project.build.directory}/${project.build.finalName}.jar</japicmp.new.classpath>
        <!-- Each module sets its published Bundle-SymbolicName explicitly (#137). -->
        <osgi.symbolic.name/>
        <!-- Empty defaults make -Djacoco.skip and caller JVM arguments safe. -->
        <surefireArgLine/>
        <argLine/>
        <coverage.line.minimum>0.990</coverage.line.minimum>
        <coverage.branch.minimum>0.985</coverage.branch.minimum>
        <osgi.import.package>*</osgi.import.package>
    </properties>

    <dependencyManagement>
        <dependencies>
            <dependency>
                <groupId>junit</groupId>
                <artifactId>junit</artifactId>
                <version>4.13.2</version>
            </dependency>
        </dependencies>
    </dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>junit</groupId>
            <artifactId>junit</artifactId>
            <scope>test</scope>
        </dependency>
    </dependencies>
    <build>
        <pluginManagement>
            <plugins>
                <!-- Project dependency management does not affect Maven plugin
                     realms. These leaf/intermediate pins replace advisory-affected
                     transitives while their current upstream plugins catch up. -->
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-clean-plugin</artifactId>
                    <version>3.5.0</version>
                    <dependencies>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>4.0.3</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-resources-plugin</artifactId>
                    <version>3.5.0</version>
                    <dependencies>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>3.6.2</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-install-plugin</artifactId>
                    <version>3.2.0</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-deploy-plugin</artifactId>
                    <version>3.2.0</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-enforcer-plugin</artifactId>
                    <version>3.6.3</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-dependency-plugin</artifactId>
                    <version>3.11.0</version>
                    <dependencies>
                        <dependency><groupId>commons-beanutils</groupId><artifactId>commons-beanutils</artifactId><version>1.11.0</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-help-plugin</artifactId>
                    <version>3.5.2</version>
                    <dependencies>
                        <dependency><groupId>org.jsoup</groupId><artifactId>jsoup</artifactId><version>1.23.2</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-wrapper-plugin</artifactId>
                    <version>3.3.4</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-checkstyle-plugin</artifactId>
                    <version>3.6.0</version>
                </plugin>
                <!-- Maven's implicit site lifecycle is pinned and disabled, never published. -->
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-site-plugin</artifactId>
                    <version>3.22.0</version>
                    <configuration><skip>true</skip><skipDeploy>true</skipDeploy></configuration>
                </plugin>
                <!-- Forked JSP engines use plugin-only dependencies, never the library test classpath. -->
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-antrun-plugin</artifactId>
                    <version>3.2.0</version>
                    <dependencies>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>4.0.3</version></dependency>
                    </dependencies>
                    <executions>
                        <execution>
                            <id>packaged-jsp-engine</id>
                            <phase>verify</phase>
                            <goals><goal>run</goal></goals>
                            <configuration>
                                <skip>${skipTests}</skip>
                                <target>
                                    <mkdir dir="${project.build.directory}/jsp-engine/classes"/>
                                    <javac srcdir="${project.basedir}/../compatibility/jsp-engine/src"
                                           destdir="${project.build.directory}/jsp-engine/classes"
                                           release="17" encoding="UTF-8" includeantruntime="false">
                                        <classpath refid="maven.plugin.classpath"/>
                                    </javac>
                                    <java classname="fixture.JspEngineTest" fork="true" failonerror="true" timeout="180000">
                                        <classpath>
                                            <path refid="maven.plugin.classpath"/>
                                            <pathelement location="${project.build.directory}/jsp-engine/classes"/>
                                        </classpath>
                                        <jvmarg value="-Duser.language=en"/>
                                        <jvmarg value="-Duser.country=US"/>
                                        <arg value="${project.basedir}/../core/target/encoder-${project.version}.jar"/>
                                        <arg value="${project.build.directory}/${project.build.finalName}.jar"/>
                                        <arg value="${project.build.directory}/jsp-engine"/>
                                    </java>
                                </target>
                            </configuration>
                        </execution>
                    </executions>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-compiler-plugin</artifactId>
                    <version>3.16.0</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-jar-plugin</artifactId>
                    <version>3.5.1</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-source-plugin</artifactId>
                    <version>3.4.0</version>
                    <dependencies>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-archiver</artifactId><version>4.14.0</version></dependency>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>4.0.3</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-javadoc-plugin</artifactId>
                    <version>3.12.0</version>
                    <dependencies>
                        <dependency><groupId>commons-beanutils</groupId><artifactId>commons-beanutils</artifactId><version>1.11.0</version></dependency>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-archiver</artifactId><version>4.14.0</version></dependency>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>4.0.3</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.jacoco</groupId>
                    <artifactId>jacoco-maven-plugin</artifactId>
                    <version>0.8.15</version>
                    <dependencies>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>3.6.2</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-failsafe-plugin</artifactId>
                    <version>3.6.0</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-surefire-plugin</artifactId>
                    <version>3.6.0</version>
                </plugin>
                <plugin>
                    <groupId>org.apache.maven.plugins</groupId>
                    <artifactId>maven-gpg-plugin</artifactId>
                    <version>3.2.8</version>
                    <dependencies>
                        <!-- Keep the optional Java signer and plugin utilities on reviewed patched lines. -->
                        <dependency><groupId>org.bouncycastle</groupId><artifactId>bcpg-jdk18on</artifactId><version>1.86</version></dependency>
                        <dependency><groupId>org.bouncycastle</groupId><artifactId>bcprov-jdk18on</artifactId><version>1.86</version></dependency>
                        <dependency><groupId>org.bouncycastle</groupId><artifactId>bcutil-jdk18on</artifactId><version>1.86</version></dependency>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>3.6.2</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.apache.felix</groupId>
                    <artifactId>maven-bundle-plugin</artifactId>
                    <version>6.2.0</version>
                    <dependencies>
                        <dependency><groupId>commons-beanutils</groupId><artifactId>commons-beanutils</artifactId><version>1.11.0</version></dependency>
                        <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-archiver</artifactId><version>4.14.0</version></dependency>
                    </dependencies>
                </plugin>
                <plugin>
                    <groupId>org.codehaus.mojo</groupId>
                    <artifactId>versions-maven-plugin</artifactId>
                    <version>2.22.0</version>
                </plugin>
                <!-- Run the japicmp engine directly. The Maven report wrapper pulls
                     obsolete site/reporting libraries into the build-only graph. -->
                <plugin>
                    <groupId>org.codehaus.mojo</groupId>
                    <artifactId>exec-maven-plugin</artifactId>
                    <version>3.6.4</version>
                    <dependencies>
                        <dependency>
                            <groupId>com.github.siom79.japicmp</groupId>
                            <artifactId>japicmp</artifactId>
                            <version>0.26.2</version>
                        </dependency>
                    </dependencies>
                    <executions>
                        <execution>
                            <id>public-api-baseline</id>
                            <phase>verify</phase>
                            <goals><goal>java</goal></goals>
                            <configuration>
                                <mainClass>japicmp.JApiCmp</mainClass>
                                <includeProjectDependencies>false</includeProjectDependencies>
                                <includePluginDependencies>true</includePluginDependencies>
                                <blockSystemExit>true</blockSystemExit>
                                <arguments>
                                    <argument>--old</argument>
                                    <argument>${settings.localRepository}/org/owasp/encoder/${project.artifactId}/${public.api.baseline.version}/${project.artifactId}-${public.api.baseline.version}.jar</argument>
                                    <argument>--new</argument>
                                    <argument>${project.build.directory}/${project.build.finalName}.jar</argument>
                                    <argument>--old-classpath</argument>
                                    <argument>${japicmp.old.classpath}</argument>
                                    <argument>--new-classpath</argument>
                                    <argument>${japicmp.new.classpath}</argument>
                                    <argument>--only-modified</argument>
                                    <argument>--error-on-binary-incompatibility</argument>
                                    <argument>--error-on-source-incompatibility</argument>
                                </arguments>
                            </configuration>
                        </execution>
                    </executions>
                </plugin>
                <plugin>
                    <groupId>org.sonatype.central</groupId>
                    <artifactId>central-publishing-maven-plugin</artifactId>
                    <version>0.11.0</version>
                </plugin>
            </plugins>
        </pluginManagement>

        <plugins>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-enforcer-plugin</artifactId>
                <executions>
                    <execution>
                        <id>build-policy</id>
                        <phase>validate</phase>
                        <goals><goal>enforce</goal></goals>
                        <configuration>
                            <rules>
                                <requireMavenVersion><version>[3.9.16,)</version></requireMavenVersion>
                                <requireJavaVersion><version>[17,)</version></requireJavaVersion>
                                <banDuplicatePomDependencyVersions/>
                                <dependencyConvergence/>
                                <requireUpperBoundDeps/>
                                <requirePluginVersions>
                                    <phases>clean,verify,install,deploy</phases>
                                </requirePluginVersions>
                            </rules>
                        </configuration>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-checkstyle-plugin</artifactId>
                <dependencies>
                    <dependency>
                        <groupId>com.puppycrawl.tools</groupId>
                        <artifactId>checkstyle</artifactId>
                        <!-- Last Java 17-compatible line; 13+ requires Java 21. -->
                        <version>12.3.1</version>
                    </dependency>
                    <dependency><groupId>org.apache.commons</groupId><artifactId>commons-lang3</artifactId><version>3.20.0</version></dependency>
                    <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-archiver</artifactId><version>4.14.0</version></dependency>
                    <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>4.0.3</version></dependency>
                </dependencies>
                <configuration>
                    <configLocation>${maven.multiModuleProjectDirectory}/src/main/config/checkstyle.xml</configLocation>
                    <headerLocation>${maven.multiModuleProjectDirectory}/src/main/config/checkstyle-header.txt</headerLocation>
                    <!-- Checkstyle 12's parser cannot parse module declarations; packaged JPMS guards cover them. -->
                    <excludes>module-info.java</excludes>
                    <includeResources>false</includeResources>
                    <includeTestResources>false</includeTestResources>
                    <sourceDirectories>
                        <sourceDirectory>${project.basedir}/src/main/java</sourceDirectory>
                        <sourceDirectory>${project.basedir}/src/main/java9</sourceDirectory>
                    </sourceDirectories>
                </configuration>
                <executions>
                    <execution>
                        <id>main-source-policy</id>
                        <phase>validate</phase>
                        <goals><goal>check</goal></goals>
                    </execution>
                </executions>
            </plugin>
            <!-- The Java 8 release target is also checked against JRE API signatures. -->
            <plugin>
                <groupId>org.codehaus.mojo</groupId>
                <artifactId>animal-sniffer-maven-plugin</artifactId>
                <version>1.28</version>
                <configuration>
                    <signature>
                        <groupId>org.codehaus.mojo.signature</groupId>
                        <artifactId>java18</artifactId>
                        <version>1.0</version>
                    </signature>
                </configuration>
                <executions>
                    <execution>
                        <id>java-8-api-baseline</id>
                        <phase>verify</phase>
                        <goals><goal>check</goal></goals>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-compiler-plugin</artifactId>
                <configuration>
                    <release>8</release>
                </configuration>
                <executions>
                    <execution>
                        <id>compile-java-9</id>
                        <phase>compile</phase>
                        <goals>
                            <goal>compile</goal>
                        </goals>
                        <configuration>
                            <release>9</release>
                            <compileSourceRoots>
                                <compileSourceRoot>${project.basedir}/src/main/java9</compileSourceRoot>
                            </compileSourceRoots>
                            <multiReleaseOutput>true</multiReleaseOutput>
                        </configuration>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.apache.felix</groupId>
                <artifactId>maven-bundle-plugin</artifactId>
                <executions>
                    <execution>
                        <id>default-bundle</id>
                        <phase>process-classes</phase>
                        <goals>
                            <goal>manifest</goal>
                        </goals>
                        <configuration>
                            <excludeDependencies>true</excludeDependencies>
                            <instructions>
                                <_reproducible>true</_reproducible>
                                <_noextraheaders>true</_noextraheaders>
                                <_noee>true</_noee>
                                <!-- OSGi frameworks before R7 reject java.* imports. -->
                                <_noimportjava>true</_noimportjava>
                                <_nouses>true</_nouses>
                                <!-- This legacy property controls only the manifest fallback name, not the explicit JPMS descriptor. -->
                                <Automatic-Module-Name>${jigsaw.module.name}</Automatic-Module-Name>
                                <Export-Package>!META-INF.versions.*,*</Export-Package>
                                <!-- Frozen published identity; do not derive it from the artifactId. -->
                                <Bundle-SymbolicName>${osgi.symbolic.name}</Bundle-SymbolicName>
                                <Bundle-Vendor>${project.organization.name}</Bundle-Vendor>
                                <Bundle-DocURL>${project.url}</Bundle-DocURL>
                                <!-- Dependencies are excluded from bnd's analysis, so version ranges
                                     for imported packages must be stated explicitly per module. -->
                                <Import-Package>${osgi.import.package}</Import-Package>
                            </instructions>
                        </configuration>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.jacoco</groupId>
                <artifactId>jacoco-maven-plugin</artifactId>
                <executions>
                    <execution>
                        <id>prepare-agent</id>
                        <goals>
                            <goal>prepare-agent</goal>
                        </goals>
                        <configuration>
                            <propertyName>surefireArgLine</propertyName>
                            <append>true</append>
                        </configuration>
                    </execution>
                    <execution>
                        <id>coverage-report</id>
                        <phase>verify</phase>
                        <goals><goal>report</goal><goal>check</goal></goals>
                        <configuration>
                            <rules>
                                <rule>
                                    <element>BUNDLE</element>
                                    <limits>
                                        <limit><counter>LINE</counter><value>COVEREDRATIO</value><minimum>${coverage.line.minimum}</minimum></limit>
                                        <limit><counter>BRANCH</counter><value>COVEREDRATIO</value><minimum>${coverage.branch.minimum}</minimum></limit>
                                    </limits>
                                </rule>
                            </rules>
                        </configuration>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-surefire-plugin</artifactId>
                <configuration>
                    <argLine>@{surefireArgLine} @{argLine}</argLine>
                </configuration>
            </plugin>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-jar-plugin</artifactId>
                <configuration>
                    <archive>
                        <manifestFile>${project.build.outputDirectory}/META-INF/MANIFEST.MF</manifestFile>
                        <manifestEntries>
                            <Multi-Release>true</Multi-Release>
                        </manifestEntries>
                    </archive>
                </configuration>
            </plugin>
            <plugin>
                <groupId>org.codehaus.mojo</groupId>
                <artifactId>build-helper-maven-plugin</artifactId>
                <version>3.6.2</version>
                <executions>
                    <execution>
                        <id>module-descriptor-sources</id>
                        <!-- After resource copying/compilation: source JARs only, never Java 8 compilation. -->
                        <phase>prepare-package</phase>
                        <goals><goal>add-resource</goal></goals>
                        <configuration>
                            <skipAddResourceIfMissing>true</skipAddResourceIfMissing>
                            <resources>
                                <resource>
                                    <directory>${project.basedir}/src/main/java9</directory>
                                    <targetPath>META-INF/versions/9</targetPath>
                                </resource>
                            </resources>
                        </configuration>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-source-plugin</artifactId>
                <executions>
                    <execution>
                        <id>attach-sources</id>
                        <phase>package</phase>
                        <goals>
                            <goal>jar-no-fork</goal>
                        </goals>
                    </execution>
                </executions>
            </plugin>
            <plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-javadoc-plugin</artifactId>
                <configuration>
                    <source>8</source>
                    <failOnError>true</failOnError>
                </configuration>
                <executions>
                    <execution>
                        <id>attach-javadocs</id>
                        <phase>package</phase>
                        <goals>
                            <goal>jar</goal>
                        </goals>
                    </execution>
                </executions>
            </plugin>
        </plugins>
    </build>
    <profiles>
        <profile>
            <id>sign-artifacts</id>
            <activation>
                <property>
                    <name>performRelease</name>
                    <value>true</value>
                </property>
            </activation>
            <build>
                <plugins>
                    <plugin>
                        <groupId>org.apache.maven.plugins</groupId>
                        <artifactId>maven-enforcer-plugin</artifactId>
                        <executions>
                            <execution>
                                <id>release-toolchain</id>
                                <goals><goal>enforce</goal></goals>
                                <configuration><rules>
                                    <requireJavaVersion><version>[17.0.20-1]</version></requireJavaVersion>
                                    <requireReleaseVersion/>
                                    <requireJavaVendor><includes><include>Eclipse Adoptium</include></includes></requireJavaVendor>
                                    <requireProperty><property>java.runtime.version</property><regex>17\.0\.20\.1\+1</regex></requireProperty>
                                    <requireMavenVersion><version>[3.9.16]</version></requireMavenVersion>
                                </rules></configuration>
                            </execution>
                        </executions>
                    </plugin>
                    <plugin>
                        <groupId>org.sonatype.central</groupId>
                        <artifactId>central-publishing-maven-plugin</artifactId>
                        <extensions>true</extensions>
                        <!-- Mitigate reviewed upstream publisher dependencies; isolated plugin realm only. -->
                        <dependencies>
                            <dependency><groupId>org.codehaus.plexus</groupId><artifactId>plexus-utils</artifactId><version>3.6.2</version></dependency>
                            <dependency><groupId>com.fasterxml.jackson.core</groupId><artifactId>jackson-databind</artifactId><version>2.22.3</version></dependency>
                            <dependency><groupId>com.fasterxml.jackson.core</groupId><artifactId>jackson-core</artifactId><version>2.22.3</version></dependency>
                            <dependency><groupId>com.fasterxml.jackson.core</groupId><artifactId>jackson-annotations</artifactId><version>2.22</version></dependency>
                            <dependency><groupId>org.apache.httpcomponents.client5</groupId><artifactId>httpclient5</artifactId><version>5.6.4</version></dependency>
                            <dependency><groupId>org.apache.httpcomponents.core5</groupId><artifactId>httpcore5</artifactId><version>5.4.4</version></dependency>
                            <dependency><groupId>org.apache.httpcomponents.core5</groupId><artifactId>httpcore5-h2</artifactId><version>5.4.4</version></dependency>
                        </dependencies>

                        <configuration>
                            <publishingServerId>central</publishingServerId>
                            <autoPublish>false</autoPublish>
                            <excludeArtifacts><excludeArtifact>jakarta-test</excludeArtifact></excludeArtifacts>
                        </configuration>
                    </plugin>
                    <plugin>
                        <groupId>org.apache.maven.plugins</groupId>
                        <artifactId>maven-gpg-plugin</artifactId>
                        <configuration>
                            <bestPractices>true</bestPractices>
                        </configuration>
                        <executions>
                            <execution>
                                <id>sign-artifacts</id>
                                <goals>
                                    <goal>sign</goal>
                                </goals>
                            </execution>
                        </executions>
                    </plugin>
                </plugins>
            </build>
        </profile>
        <profile>
            <id>testJakarta</id>
            <activation>
                <activeByDefault>false</activeByDefault>
            </activation>
            <modules>
                <module>jakarta-test</module>
            </modules>
        </profile>
    </profiles>
</project>
