Skip to content

Sync fork with upstream WebGoat/WebGoat:main - #41

Closed
fgibelin wants to merge 8 commits into
fgibelin:mainfrom
WebGoat:main
Closed

fgibelin wants to merge 8 commits into
fgibelin:mainfrom
WebGoat:main

Conversation

@fgibelin

Copy link
Copy Markdown
Owner

Syncs fgibelin/WebGoat:main with the latest 8 commits from upstream WebGoat/WebGoat:main.

Commits

SHA Date Summary
1c37c553 2026-09-22 chore: back to snapshot after v2026.4 (WebGoat#2540)
98fd897a 2026-09-22 chore: bump com.diffplug.spotless:spotless-maven-plugin (WebGoat#2536)
b27a53ad 2026-09-22 test(xxe): use deterministic entity targets (WebGoat#2547)
c037c956 2026-09-22 chore: bump com.auth0:java-jwt from 4.6.0 to 4.6.1 (WebGoat#2538)
c92642df 2026-09-23 feat(cryptography): add HMAC timing attack lesson (WebGoat#2548)
d15692b3 2026-09-23 test(sql-injection): cover mitigation form submissions
f1a569c8 2026-09-23 ci: run matrix builds in parallel
3284a8e4 2026-09-23 feat(http): add parameter pollution lesson

Notes

  • Two new lessons (HMAC timing attack, HTTP parameter pollution), dependency bumps, test hardening, and a CI parallelisation change.
  • Supersedes Sync upstream main from WebGoat/WebGoat #40, which was stale and contained only the first 2 of these commits.

github-actions Bot and others added 8 commits September 22, 2026 09:03
Files changed:
M	pom.xml

Co-authored-by: nbaars <nbaars@users.noreply.github.com>
Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.10.1 to 3.10.2.
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.10.1...maven/3.10.2)

---
updated-dependencies:
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Root directory contents vary across CI runners, so XXE tests need a controlled file to verify external entity expansion reliably.
Bumps [com.auth0:java-jwt](https://github.com/auth0/java-jwt) from 4.6.0 to 4.6.1.
- [Release notes](https://github.com/auth0/java-jwt/releases)
- [Changelog](https://github.com/auth0/java-jwt/blob/master/CHANGELOG.md)
- [Commits](auth0/java-jwt@4.6.0...4.6.1)

---
updated-dependencies:
- dependency-name: com.auth0:java-jwt
  dependency-version: 4.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Teach how secret-dependent tag comparisons leak HMAC bytes and how repeated timing measurements can recover them under noise.
Existing endpoint tests bypass the lesson forms and miss incorrect action URLs that return 404. Add regression coverage for both input validation forms to prevent this failure from returning.

Closes: #2502
Run the operating-system builds concurrently now that the flaky tests have been stabilized.
Teach how duplicate parameters can cause validation and execution to interpret the same request differently, including safe handling guidance.
@fgibelin

Copy link
Copy Markdown
Owner Author

Superseded by #42.

This cross-fork PR (head WebGoat:main) hit merge conflicts in the two XXE test files, and a cross-fork PR has no writable head branch to commit a resolution to. #42 does the same sync from a branch in this fork with the conflicts resolved.

@fgibelin fgibelin closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants