Bump LibreOffice library odfdom-java to 0.12.0, require JDK 11+ for generating Calc file ODS - #684
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR upgrades the odfdom-java library from version 0.9.0 to 0.12.0 to address security vulnerabilities in the older version. The upgrade requires JDK 11+ for generating LibreOffice Calc (ODS) files, implemented using a Multi-Release JAR (MRJAR) pattern to maintain backward compatibility with JDK 8.
Key changes:
- Upgraded odfdom-java dependency to 0.12.0 and added xml-apis 1.4.01 for JDK 8 compatibility
- Implemented MRJAR pattern with JDK 8 stub throwing UnsupportedOperationException and full JDK 11+ implementation
- Added JDK version check in tests and integration test requirements
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated 7 comments.
Show a summary per file
| File | Description |
|---|---|
| pom.xml | Updated odfdom-java to 0.12.0, added xml-apis dependency, configured MRJAR profile with compiler and surefire plugins |
| src/main/java/org/codehaus/mojo/license/extended/spreadsheet/CalcFileWriter.java | JDK 8 stub implementation throwing UnsupportedOperationException |
| src/main/java11/org/codehaus/mojo/license/extended/spreadsheet/CalcFileWriter.java | Complete JDK 11+ implementation for ODS file generation |
| src/test/java/org/codehaus/mojo/license/download/LicenseSummaryTest.java | Added version check to conditionally test ODS generation or exception handling |
| src/main/java/org/codehaus/mojo/license/utils/MojoHelper.java | Fixed URL concatenation to prevent double slashes when baseUrl already ends with "/" |
| src/main/java/org/codehaus/mojo/license/AbstractDownloadLicensesMojo.java | Added documentation noting JDK 11+ requirement for ODS file generation |
| src/it/aggregate-download-licenses-extended-spreadsheet/invoker.properties | Set minimum JDK version to 11+ for integration test |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
slawekjaranowski
force-pushed
the
bump-odfdom-java
branch
2 times, most recently
from
December 1, 2025 22:16
6dd29bf to
5aaf8ac
Compare
slawekjaranowski
force-pushed
the
bump-odfdom-java
branch
from
January 1, 2026 20:30
5aaf8ac to
fa29cc9
Compare
olamy
reviewed
Jan 4, 2026
…enerating Calc file ODS Old library contains security issues so should be updated, hope feature is not widely used, so we can bump and require JDK 11+ for this
slawekjaranowski
force-pushed
the
bump-odfdom-java
branch
from
January 4, 2026 09:57
fa29cc9 to
aeb937f
Compare
This was referenced Aug 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Old library contains security issues so should be updated, hope feature is not widely used, so we can bump and require JDK 11+ for this