{
  "_class" : "org.jenkinsci.plugins.workflow.job.WorkflowRun",
  "actions" : [
    {
      "_class" : "hudson.model.CauseAction",
      "causes" : [
        {
          "_class" : "hudson.triggers.TimerTrigger$TimerTriggerCause",
          "shortDescription" : "Lancé par une alarme périodique"
        }
      ]
    },
    {
      "_class" : "hudson.model.ParametersAction",
      "parameters" : [
        {
          "_class" : "hudson.model.BooleanParameterValue",
          "name" : "SKIP_TEST",
          "value" : False
        },
        {
          "_class" : "hudson.model.BooleanParameterValue",
          "name" : "SKIP_QUALITY",
          "value" : False
        }
      ]
    },
    {
      "_class" : "org.jenkinsci.plugins.workflow.libs.LibrariesAction"
    },
    {
      
    },
    {
      "_class" : "org.jenkinsci.plugins.workflow.cps.EnvActionImpl"
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/master" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 571,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
            "branch" : [
              {
                "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
                "name" : "refs/remotes/origin/master"
              }
            ]
          },
          "revision" : {
            "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
            "branch" : [
              {
                "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
                "name" : "refs/remotes/origin/master"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
        "branch" : [
          {
            "SHA1" : "56f5661a313b8828cac18f92b68f2f116fbd2cc2",
            "name" : "refs/remotes/origin/master"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Jenkins-Pipelines.git"
      ],
      "scmName" : ""
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/6.2.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 180,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f",
            "branch" : [
              {
                "SHA1" : "45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f",
            "branch" : [
              {
                "SHA1" : "45e0d31d27a05fd6c36b5f7bd604a0d05f7f378f",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.3.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 302,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "6df43e66c82d74fdaf07c75d56db339cf3491364",
            "branch" : [
              {
                "SHA1" : "6df43e66c82d74fdaf07c75d56db339cf3491364",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "6df43e66c82d74fdaf07c75d56db339cf3491364",
            "branch" : [
              {
                "SHA1" : "6df43e66c82d74fdaf07c75d56db339cf3491364",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.4.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 571,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
            "branch" : [
              {
                "SHA1" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
            "branch" : [
              {
                "SHA1" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.1.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 43,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31",
            "branch" : [
              {
                "SHA1" : "a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31",
            "branch" : [
              {
                "SHA1" : "a3e9b3a1a829e2b076e72afa8bf8da6253ba6b31",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
        "branch" : [
          {
            "SHA1" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
            "name" : "refs/remotes/origin/6.4.x"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Core"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/6.2.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 179,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "6976f0d418d1eb565dded101d00140960944e6aa",
            "branch" : [
              {
                "SHA1" : "6976f0d418d1eb565dded101d00140960944e6aa",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "6976f0d418d1eb565dded101d00140960944e6aa",
            "branch" : [
              {
                "SHA1" : "6976f0d418d1eb565dded101d00140960944e6aa",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.3.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 302,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "f1c18f5b16ecf085b04a36a636aa4aa26ec5d773",
            "branch" : [
              {
                "SHA1" : "f1c18f5b16ecf085b04a36a636aa4aa26ec5d773",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "f1c18f5b16ecf085b04a36a636aa4aa26ec5d773",
            "branch" : [
              {
                "SHA1" : "f1c18f5b16ecf085b04a36a636aa4aa26ec5d773",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.4.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 571,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
            "branch" : [
              {
                "SHA1" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
            "branch" : [
              {
                "SHA1" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.1.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 43,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "9dbcbf90b830646ccd42fb388d09dbe09ecea4e6",
            "branch" : [
              {
                "SHA1" : "9dbcbf90b830646ccd42fb388d09dbe09ecea4e6",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "9dbcbf90b830646ccd42fb388d09dbe09ecea4e6",
            "branch" : [
              {
                "SHA1" : "9dbcbf90b830646ccd42fb388d09dbe09ecea4e6",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
        "branch" : [
          {
            "SHA1" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
            "name" : "refs/remotes/origin/6.4.x"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Components"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/6.2.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 179,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "b3b8a633d5a98083849becc7464aebbca4218501",
            "branch" : [
              {
                "SHA1" : "b3b8a633d5a98083849becc7464aebbca4218501",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "b3b8a633d5a98083849becc7464aebbca4218501",
            "branch" : [
              {
                "SHA1" : "b3b8a633d5a98083849becc7464aebbca4218501",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.3.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 302,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "586ebdd23e10f812e41a52cbf1a3a7f4a81fe924",
            "branch" : [
              {
                "SHA1" : "586ebdd23e10f812e41a52cbf1a3a7f4a81fe924",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "586ebdd23e10f812e41a52cbf1a3a7f4a81fe924",
            "branch" : [
              {
                "SHA1" : "586ebdd23e10f812e41a52cbf1a3a7f4a81fe924",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.4.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 571,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "f105160616b668c112072a2f4714b531c52c98bc",
            "branch" : [
              {
                "SHA1" : "f105160616b668c112072a2f4714b531c52c98bc",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "f105160616b668c112072a2f4714b531c52c98bc",
            "branch" : [
              {
                "SHA1" : "f105160616b668c112072a2f4714b531c52c98bc",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.1.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 43,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "070793013d99eb148b16b15d6a191b20b72bc82c",
            "branch" : [
              {
                "SHA1" : "070793013d99eb148b16b15d6a191b20b72bc82c",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "070793013d99eb148b16b15d6a191b20b72bc82c",
            "branch" : [
              {
                "SHA1" : "070793013d99eb148b16b15d6a191b20b72bc82c",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "f105160616b668c112072a2f4714b531c52c98bc",
        "branch" : [
          {
            "SHA1" : "f105160616b668c112072a2f4714b531c52c98bc",
            "name" : "refs/remotes/origin/6.4.x"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Looks"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/6.2.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 179,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "abe99f69032413c083fb9ee7a98afc1e2ab5114d",
            "branch" : [
              {
                "SHA1" : "abe99f69032413c083fb9ee7a98afc1e2ab5114d",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "abe99f69032413c083fb9ee7a98afc1e2ab5114d",
            "branch" : [
              {
                "SHA1" : "abe99f69032413c083fb9ee7a98afc1e2ab5114d",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.3.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 302,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "146430cd63566b3be410c8dd534faa57033583b3",
            "branch" : [
              {
                "SHA1" : "146430cd63566b3be410c8dd534faa57033583b3",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "146430cd63566b3be410c8dd534faa57033583b3",
            "branch" : [
              {
                "SHA1" : "146430cd63566b3be410c8dd534faa57033583b3",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.4.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 571,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "f9a3cc8ddfdefbb340e23594a0d441da1d2cd613",
            "branch" : [
              {
                "SHA1" : "f9a3cc8ddfdefbb340e23594a0d441da1d2cd613",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "f9a3cc8ddfdefbb340e23594a0d441da1d2cd613",
            "branch" : [
              {
                "SHA1" : "f9a3cc8ddfdefbb340e23594a0d441da1d2cd613",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.1.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 43,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "62ef5e63f545c1d332fb8e528897aff1fac54150",
            "branch" : [
              {
                "SHA1" : "62ef5e63f545c1d332fb8e528897aff1fac54150",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "62ef5e63f545c1d332fb8e528897aff1fac54150",
            "branch" : [
              {
                "SHA1" : "62ef5e63f545c1d332fb8e528897aff1fac54150",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "f9a3cc8ddfdefbb340e23594a0d441da1d2cd613",
        "branch" : [
          {
            "SHA1" : "f9a3cc8ddfdefbb340e23594a0d441da1d2cd613",
            "name" : "refs/remotes/origin/6.4.x"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Setup"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/6.2.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 179,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "c96d415a32db2f558555695b382b89c11ac347be",
            "branch" : [
              {
                "SHA1" : "c96d415a32db2f558555695b382b89c11ac347be",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "c96d415a32db2f558555695b382b89c11ac347be",
            "branch" : [
              {
                "SHA1" : "c96d415a32db2f558555695b382b89c11ac347be",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.3.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 302,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "10719018413e414cfa70c0f64a945a72670797f4",
            "branch" : [
              {
                "SHA1" : "10719018413e414cfa70c0f64a945a72670797f4",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "10719018413e414cfa70c0f64a945a72670797f4",
            "branch" : [
              {
                "SHA1" : "10719018413e414cfa70c0f64a945a72670797f4",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.4.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 571,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "4c911d0c826d86eae553a296dd6f65961fc161ae",
            "branch" : [
              {
                "SHA1" : "4c911d0c826d86eae553a296dd6f65961fc161ae",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "4c911d0c826d86eae553a296dd6f65961fc161ae",
            "branch" : [
              {
                "SHA1" : "4c911d0c826d86eae553a296dd6f65961fc161ae",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.1.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 43,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "2c1de09b276e4aa8622563451ebd70a4f24759ce",
            "branch" : [
              {
                "SHA1" : "2c1de09b276e4aa8622563451ebd70a4f24759ce",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "2c1de09b276e4aa8622563451ebd70a4f24759ce",
            "branch" : [
              {
                "SHA1" : "2c1de09b276e4aa8622563451ebd70a4f24759ce",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "4c911d0c826d86eae553a296dd6f65961fc161ae",
        "branch" : [
          {
            "SHA1" : "4c911d0c826d86eae553a296dd6f65961fc161ae",
            "name" : "refs/remotes/origin/6.4.x"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Distribution"
      ],
      "scmName" : ""
    },
    {
      "_class" : "hudson.plugins.git.util.BuildData",
      "buildsByBranchName" : {
        "refs/remotes/origin/6.2.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 179,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "1bdb8f99972aa96dacfc6d8775a7364ab6e845c2",
            "branch" : [
              {
                "SHA1" : "1bdb8f99972aa96dacfc6d8775a7364ab6e845c2",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "1bdb8f99972aa96dacfc6d8775a7364ab6e845c2",
            "branch" : [
              {
                "SHA1" : "1bdb8f99972aa96dacfc6d8775a7364ab6e845c2",
                "name" : "refs/remotes/origin/6.2.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.3.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 302,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "e6cf90efb933ea1d65558af1cade3056ac4b6462",
            "branch" : [
              {
                "SHA1" : "e6cf90efb933ea1d65558af1cade3056ac4b6462",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "e6cf90efb933ea1d65558af1cade3056ac4b6462",
            "branch" : [
              {
                "SHA1" : "e6cf90efb933ea1d65558af1cade3056ac4b6462",
                "name" : "refs/remotes/origin/6.3.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.4.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 571,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "27fc17db8fc8e443cd002cec7d78fbad61804ec8",
            "branch" : [
              {
                "SHA1" : "27fc17db8fc8e443cd002cec7d78fbad61804ec8",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "27fc17db8fc8e443cd002cec7d78fbad61804ec8",
            "branch" : [
              {
                "SHA1" : "27fc17db8fc8e443cd002cec7d78fbad61804ec8",
                "name" : "refs/remotes/origin/6.4.x"
              }
            ]
          }
        },
        "refs/remotes/origin/6.1.x" : {
          "_class" : "hudson.plugins.git.util.Build",
          "buildNumber" : 43,
          "buildResult" : None,
          "marked" : {
            "SHA1" : "64a1ed5c344bf6e81820366b63120c460193579c",
            "branch" : [
              {
                "SHA1" : "64a1ed5c344bf6e81820366b63120c460193579c",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          },
          "revision" : {
            "SHA1" : "64a1ed5c344bf6e81820366b63120c460193579c",
            "branch" : [
              {
                "SHA1" : "64a1ed5c344bf6e81820366b63120c460193579c",
                "name" : "refs/remotes/origin/6.1.x"
              }
            ]
          }
        }
      },
      "lastBuiltRevision" : {
        "SHA1" : "27fc17db8fc8e443cd002cec7d78fbad61804ec8",
        "branch" : [
          {
            "SHA1" : "27fc17db8fc8e443cd002cec7d78fbad61804ec8",
            "name" : "refs/remotes/origin/6.4.x"
          }
        ]
      },
      "remoteUrls" : [
        "https://github.com/Silverpeas/Silverpeas-Assembly"
      ],
      "scmName" : ""
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.sonar.action.SonarAnalysisAction",
      "ceTaskId" : "AaD2JBITnW7s-NNcLCz7",
      "credentialsId" : None,
      "installationName" : "Silverpeas SonarCloud",
      "installationUrl" : "https://sonarcloud.io",
      "new" : True,
      "serverUrl" : "https://sonarcloud.io",
      "skipped" : False,
      "sonarqubeDashboardUrl" : "https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&branch=6.4.x"
    },
    {
      
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.sonar.action.SonarAnalysisAction",
      "ceTaskId" : "AaD2RaVYkj6CGoBn8Dna",
      "credentialsId" : None,
      "installationName" : "Silverpeas SonarCloud",
      "installationUrl" : "https://sonarcloud.io",
      "new" : True,
      "serverUrl" : "https://sonarcloud.io",
      "skipped" : False,
      "sonarqubeDashboardUrl" : "https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&branch=6.4.x"
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      
    },
    {
      "_class" : "hudson.plugins.sonar.action.SonarBuildBadgeAction",
      "url" : None
    },
    {
      
    },
    {
      "_class" : "org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction"
    },
    {
      "_class" : "org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction"
    },
    {
      
    },
    {
      "_class" : "org.jenkinsci.plugins.workflow.job.views.FlowGraphAction"
    },
    {
      
    },
    {
      
    }
  ],
  "artifacts" : [
    {
      "displayPath" : "build.yaml",
      "fileName" : "build.yaml",
      "relativePath" : "target/build.yaml"
    }
  ],
  "building" : False,
  "description" : None,
  "displayName" : "6.4.8-build261001",
  "duration" : 9118224,
  "estimatedDuration" : 5497799,
  "executor" : None,
  "fullDisplayName" : "Silverpeas_Stable_AutoDeploy 6.4.8-build261001",
  "id" : "571",
  "keepLog" : False,
  "number" : 571,
  "queueId" : 64011,
  "result" : "SUCCESS",
  "timestamp" : 1790829960596,
  "url" : "https://integration.silverpeas.org/jenkins/job/Silverpeas_Stable_AutoDeploy/571/",
  "changeSets" : [
    {
      "_class" : "hudson.plugins.git.GitChangeSetList",
      "items" : [
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java",
            "core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java",
            "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
          ],
          "commitId" : "cbca010a1bf431ccce251585dcf892700d9f4272",
          "timestamp" : 1790599035000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460\u000a\u000a(GitHub issues, reported against 6.4.6)\u000a\u000aThe three reported stored XSS rely on an event callback attribute carried by an\u000aelement the browser fails to load on purpose. Such a declaration was detected by\u000athe \\s+on\\w+\\s*= pattern, which expects a whitespace before the attribute name.\u000aAccording to the HTML tokenizer, an attribute name is also expected right after\u000athe closing quote of the previous attribute value (a\u000amissing-whitespace-between-attributes parse error, whose recovery is mandated by\u000athe specification) and right after a solidus. So the following did declare an\u000aonerror callback the browsers do run, while going through the filter:\u000a\u000a  <img src=\"x\"onerror=alert(1)>\u000a\u000aThe pattern now accepts these separators as well.\u000a\u000aNote this filter is an input guard, not an output encoding: it narrows the\u000areachability of the three flaws but it doesn't fix the rendering code itself.\u000a\u000aMassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports\u000aon their actual endpoints and parameters, including when they are submitted as\u000amultipart/form-data streams as the genuine forms do. It also delimits the\u000amultipart exemption, which applies to the webPages component only.\u000a\u000aTestHttpRequest.getContentType() returned null whatever the headers set on the\u000astub, which made the multipart branch untestable.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:15 +0200",
          "id" : "cbca010a1bf431ccce251585dcf892700d9f4272",
          "msg" : "Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java"
            },
            {
              "editType" : "add",
              "file" : "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-war/src/main/webapp/defaultLoginQuestion.jsp"
          ],
          "commitId" : "b8e6d6bb35fda9a02280c287662a61e7683c275a",
          "timestamp" : 1790599035000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1458\u000a\u000a(GitHub issue, reported against 6.4.6)\u000a\u000aThe login question, which any authenticated user sets from their profile, was\u000aprinted raw by a JSP scriptlet on the password reminder page, an anonymous one.\u000aAny script stored there was then run in the browser of every visitor of that\u000apage, without any login required from them. The answer to that question, itself\u000aa credential, is asked on the very same page.\u000a\u000aThe value is now HTML encoded on output, through a c:out tag. Doing so on the\u000arendering side rather than on the writing one closes both the ways the field is\u000afed: MyProfilRequestRouter, which the report points at, but also\u000aValidationQuestionHandler, which stores the question of the ValidateQuestion\u000afunction with no more filtering. It also neutralizes the values already stored.\u000a\u000aThe login of the hidden field below is encoded as well. It comes from a lookup\u000ain the database and not from the request parameter, so exploiting it would\u000arequire a login holding a quote, but the encoding costs nothing here.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:15 +0200",
          "id" : "b8e6d6bb35fda9a02280c287662a61e7683c275a",
          "msg" : "Fix vulnerability #1458",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-war/src/main/webapp/defaultLoginQuestion.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java",
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java",
            "core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java",
            "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties",
            "core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java",
            "core-library/src/integration-test/java/org/silverpeas/core/test/WarBuilder4LibCore.java",
            "core-library/src/integration-test/resources/org/silverpeas/util/security.properties",
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java",
            "core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java",
            "core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java",
            "core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java",
            "core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java",
            "core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java",
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java"
          ],
          "commitId" : "661dad84ee2e8251e0a0291c75876b2f91db5aef",
          "timestamp" : 1790599035000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1459\u000a\u000a(GitHub issue, reported against 6.4.6)\u000a\u000aThe WYSIWYG content of a form field was written into the response as raw HTML by\u000aWysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages\u000acard was run in the browser of every user viewing it. The same held for the\u000acontent of a publication, rendered by WysiwygContentRenderer, and for the two\u000aexport paths, none of which was reported.\u000a\u000aSuch a content is sanitized now, by the new SanitizeForRenderingDirective.\u000aUnlike SanitizeDirective, which keeps only a restricted set of safe elements and\u000ais left untouched for the contents extracted out of Silverpeas, this one keeps\u000athe content as it is and drops only what can act on the visitor's browser:\u000a\u000a- the elements able to run code or to take over the document, with their\u000a  content;\u000a- the event callback attributes, whatever the element carrying them;\u000a- the attributes referring a URL with a scripting scheme;\u000a- the iframes and the media whose source isn't allowed.\u000a\u000aThis is deliberate: the WYSIWYG editor is set up to accept any content\u000a(config.allowedContent = true in silverconfig.js), so an allow list applied at\u000arendering time would be narrower than what the users are entitled to write. It\u000awould in particular have dropped the media produced by the video and html5audio\u000aplugins and the rel attribute the userzoom and identitycard ones rely upon.\u000a\u000aThe parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the\u000acontent is read the way a browser reads it and the dropping can't be dodged by\u000aplaying with the HTML syntax.\u000a\u000aThe rule deciding whether the source of an iframe is allowed moves to the new\u000aEmbeddedSourceValidator class, so that the filtering of the incoming requests\u000aand this sanitization agree on it. It now serves the media as well, through the\u000anew security.external.media.hosts.allowed property. That property is shipped\u000awith the * value, which allows any host and hence preserves the behaviour of the\u000aprevious versions; setting it empty restricts the media to the ones Silverpeas\u000ahosts itself. The inlined images are kept whatever it is, being carried by the\u000acontent itself.\u000a\u000aThe mail path is deliberately left out: its images are referred by cid URLs,\u000awhich such a sanitization drops, and its content isn't rendered in the\u000aSilverpeas origin anyway.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:15 +0200",
          "id" : "661dad84ee2e8251e0a0291c75876b2f91db5aef",
          "msg" : "Fix vulnerability #1459",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java"
            },
            {
              "editType" : "edit",
              "file" : "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties"
            },
            {
              "editType" : "add",
              "file" : "core-library/src/integration-test/resources/org/silverpeas/util/security.properties"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/integration-test/java/org/silverpeas/core/test/WarBuilder4LibCore.java"
            },
            {
              "editType" : "edit",
              "file" : "core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java"
            },
            {
              "editType" : "add",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java"
            },
            {
              "editType" : "add",
              "file" : "core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java"
            },
            {
              "editType" : "edit",
              "file" : "core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java"
          ],
          "commitId" : "5ebb4137a1e0058436d4e39ec80ec42a6b9c5f91",
          "timestamp" : 1790599035000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1461\u000a\u000a(GitHub issue, reported against 6.4.6)\u000a\u000aLet the callers of HttpUtil complete the HTTP client.\u000a\u000aFixing that vulnerability requires the gallery component to request the image of\u000aa watermark with a connection timeout and without following the redirections,\u000athe latter being able to escape the verification of the address being requested.\u000a\u000ahttpClientBuilder() gives the builder of the HTTP client, already configured\u000awith the proxy of Silverpeas, so that such a caller can complete the\u000aconfiguration without having to duplicate that of the proxy. httpClient() now\u000adelegates to it and is unchanged for its own callers.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:15 +0200",
          "id" : "5ebb4137a1e0058436d4e39ec80ec42a6b9c5f91",
          "msg" : "Fix vulnerability #1461",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js",
            "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java",
            "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
          ],
          "commitId" : "2ad38c6954d3170053da74aea7d4f47a06404d63",
          "timestamp" : 1790599035000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741\u000a\u000aBoth report a stored XSS through the name of an uploaded file, one from the\u000adocument management and the other from the image upload of the WYSIWYG editor.\u000aThey share their cause: the name is written as an HTML content by the upload\u000awidget, whereas it is carried by the request and escaped on the sending side\u000aonly, which protects from nothing as a request can be forged.\u000a\u000aThe name is now set as a text. Note the formatted size which followed it was\u000aalready not displayed, html() taking a single argument, so the display is left\u000aunchanged.\u000a\u000aA scripting scheme given as the value of an attribute is detected as well by\u000aMassiveWebSecurityFilter. Such a declaration holds no on prefix and was\u000atherefore going through, and the colon introducing it is accepted written as\u000athe character itself or as any of the HTML entities standing for it, as the\u000areported payload uses \"javascript&colon;\". The data scheme is deliberately left\u000aout: the contents do embed their inlined images with it.\u000a",
          "date" : "2026-09-28 14:37:15 +0200",
          "id" : "2ad38c6954d3170053da74aea7d4f47a06404d63",
          "msg" : "Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql",
            "core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java",
            "core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java",
            "core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java"
          ],
          "commitId" : "baa73a5b26b3e593c802c659e6d67799bb92a400",
          "timestamp" : 1790599035000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Sort only the nodes of the component instance being administrated\u000a\u000aThe sorting of the nodes was granted against the component instance referred by\u000athe URL of the REST service, whereas the nodes to sort were taken from the\u000arequest body, each of them carrying the component instance it belongs to. An\u000aadministrator of any instance could hence ask to sort the nodes of another one.\u000a\u000aThe nodes are now identified within the instance of the URL, the one the\u000aauthorization has been checked against. Taking that instance from the body\u000abrought nothing: the sorting applies by nature to the instance administrated.\u000a\u000aThat wasn't enough though. NodeDAO was updating the order of a node by its\u000aidentifier only, whereas such an identifier isn't unique by itself: the root\u000anode of every component instance is numbered 0, and the ones below it can bear\u000athe same numbers from an instance to another. So the instance of the node is\u000anow part of the criteria. Beyond the authorization, this was a defect on its\u000aown: sorting the nodes of an instance was renumbering the nodes of the other\u000aones bearing the same identifiers, whoever asked for that sorting.\u000a\u000aNodeSortingIT covers the sorting of the nodes of an instance and the isolation\u000aof the other instances from it, in both directions.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:15 +0200",
          "id" : "baa73a5b26b3e593c802c659e6d67799bb92a400",
          "msg" : "Sort only the nodes of the component instance being administrated",
          "paths" : [
            {
              "editType" : "add",
              "file" : "core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql"
            },
            {
              "editType" : "edit",
              "file" : "core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java"
            },
            {
              "editType" : "add",
              "file" : "core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java"
          ],
          "commitId" : "e43a2cc2b84df2a3c699cc7d0bd7819f04af5c8e",
          "timestamp" : 1790599035000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Take into account sonarcloud feedback\u000a",
          "date" : "2026-09-28 14:37:15 +0200",
          "id" : "e43a2cc2b84df2a3c699cc7d0bd7819f04af5c8e",
          "msg" : "Take into account sonarcloud feedback",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties"
          ],
          "commitId" : "cc844d33395f7b7d1b1167d15235cf636b534293",
          "timestamp" : 1790599249000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@silverpeas.com",
          "comment" : "Now the parameter security.external.media.hosts.allowed is empty.\u000a\u000aThis means all hosts out of Silverpeas will be refused in HTML media\u000atags (video, iframe, img, ...)\u000a",
          "date" : "2026-09-28 14:40:49 +0200",
          "id" : "cc844d33395f7b7d1b1167d15235cf636b534293",
          "msg" : "Now the parameter security.external.media.hosts.allowed is empty.",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-configuration/src/main/config/properties/org/silverpeas/util/security.properties"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java",
            "core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java",
            "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java"
          ],
          "commitId" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
          "timestamp" : 1790608560000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@silverpeas.com",
          "comment" : "Fix bug-15488\u000a",
          "date" : "2026-09-28 17:16:00 +0200",
          "id" : "50d31f738f19b3d7b37a86554870383fa9d856e2",
          "msg" : "Fix bug-15488",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java"
            },
            {
              "editType" : "edit",
              "file" : "core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java"
            }
          ]
        }
      ],
      "kind" : "git"
    },
    {
      "_class" : "hudson.plugins.git.GitChangeSetList",
      "items" : [
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp",
            "forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp",
            "forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp"
          ],
          "commitId" : "6d20d3540502e348e7b4716d788dc8eb1425d9b1",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1460\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aThe title and the body of a forum message were printed raw by JSP scriptlets on\u000athe thread page, so any script posted by a user of the forum was run in the\u000abrowser of every user reading it.\u000a\u000aThe title is now HTML encoded on output, as the other JSPs of the component\u000aalready do through WebEncodeHelper. Two other raw outputs of the title, which\u000athe report doesn't mention, are encoded as well: the one of modifyMessage.jsp,\u000awhere the title lands in the value attribute of an input and is hence\u000aexploitable by escaping that attribute, and the one of editMessageKeywords.jsp.\u000a\u000aThe body is sanitized by the applySanitizeForRenderingDirective directive\u000aintroduced in Silverpeas-Core for the vulnerability #1459, which drops what can\u000aact on the visitor's browser while keeping the content as it is.\u000a\u000aNote the report also states the title pollutes the title element of the page.\u000aIt does appear there, but viewMessage.jsp already prints it through a c:out tag,\u000aso it is encoded and isn't a vector.\u000a\u000aCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "6d20d3540502e348e7b4716d788dc8eb1425d9b1",
          "msg" : "Fix vulnerability #1460",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp"
            },
            {
              "editType" : "edit",
              "file" : "forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp"
            },
            {
              "editType" : "edit",
              "file" : "forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java",
            "gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java"
          ],
          "commitId" : "508c8747e5b8116c0f642aa306a22a8ebb8c0264",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1461\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aThe image of a watermark is an instance parameter any manager of the space\u000aholding the gallery can set, and the server requests it as it is, at each media\u000acreation. It could hence be pointed at a service the server keeps for itself.\u000a\u000aSuch an URL is now verified before being requested: only the HTTP and HTTPS\u000aschemes are handled, and the host must resolve to neither a loopback nor a\u000alink-local address, so that neither the services bound to the server itself nor\u000athe metadata endpoint of a cloud provider can be reached. Every address the host\u000aresolves to is verified, otherwise a host resolving to a forbidden address\u000abeside an allowed one would go through.\u000a\u000aThe addresses of the private networks of an organization remain reachable on\u000apurpose: they are where the internal resources of an intranet legitimately live,\u000aand no address range can tell them from the internal services one would rather\u000aprotect. Only an explicit list of allowed hosts could, which is left to a\u000afurther decision.\u000a\u000aThe request is besides given a timeout and its response is no longer copied\u000awithout any bound, both being able to exhaust the resources of the server, and\u000athe redirections are no longer followed as they would escape the verification\u000aabove.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "508c8747e5b8116c0f642aa306a22a8ebb8c0264",
          "msg" : "Fix vulnerability #1461",
          "paths" : [
            {
              "editType" : "add",
              "file" : "gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java"
            },
            {
              "editType" : "edit",
              "file" : "gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp",
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp",
            "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java"
          ],
          "commitId" : "249c3e5a9115c7c560eae2043b256dddfab53378",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1462 and secure the other writings of the newsletter\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aPublishing an issue of a newsletter changes its state, stamps its publication\u000adate, notifies the subscribers and mails the external ones. It was requested by\u000aa GET, and the synchronizer token is required on a GET only when its URL holds\u000aone of a few keywords, which ValidateParution holds none of. Any logged user\u000alured into a cross-site visit was hence publishing the issue as themselves.\u000a\u000aThe publication is now submitted by POST, on which the token is required\u000awhatever the URL, through the formRequest facility which stamps it.\u000a\u000aMoreover the endpoint had no role check at all, so any reader of the newsletter\u000awas able to publish an issue and to trigger the mailing, with no luring needed.\u000aOnly its publishers and its managers can do so now.\u000a\u000aThree other writings, which the report doesn't mention, were exposed the same\u000away and are secured likewise:\u000a- resetting the content of an issue with its template, which overwrites the\u000a  content being written;\u000a- mailing an issue to oneself and to the managers, which sends the content of an\u000a  issue not published yet and was hence a way for any reader to get a draft.\u000a\u000aAs EditContent also serves the edition itself, a mere navigation which remains a\u000aGET, the reset is explicitly refused when it isn't requested by POST: submitting\u000ait by POST would otherwise protect nothing, the previous URL remaining\u000arequestable.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "249c3e5a9115c7c560eae2043b256dddfab53378",
          "msg" : "Fix vulnerability #1462 and secure the other writings of the newsletter",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp",
            "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java",
            "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp"
          ],
          "commitId" : "da97397bc61edab0e1f7156bdbf315ab64129113",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerabilities #1463\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aThe operations on the issues themselves were exposed the same way and are\u000asecured likewise: creating and modifying an issue, and modifying the headers of\u000athe newsletter, were requestable by a GET although their forms are submitted by\u000aPOST, the router not caring about the method.\u000a\u000aNone of the operations of this router had any role check, so any reader was able\u000ato write the content of an issue, to modify the headers of the newsletter, to\u000adelete issues and to read the ones being written. They are now reserved to the\u000apublishers and to the managers, but for the ones on the template and the\u000adeletion of several issues at once, reserved to the managers.\u000a\u000aReading the inlined CSS rendering of an issue is how the readers get it from the\u000alist, so the criterion there isn't the role but the issue itself: it is refused\u000ato them as long as it isn't published.\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "da97397bc61edab0e1f7156bdbf315ab64129113",
          "msg" : "Fix vulnerabilities #1463",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp"
            },
            {
              "editType" : "edit",
              "file" : "infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp",
            "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java",
            "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp",
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
          ],
          "commitId" : "217fe3edf581b66e5c9f935e9e367022e86977a6",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #1464\u000a\u000a(GitHub issue of Silverpeas-Core, reported against 6.4.6)\u000a\u000aLoading publications into the clipboard and pasting them under another topic\u000awere requestable by a GET, so any logged user lured into a cross-site visit was\u000amoving publications as themselves.\u000a\u000aThe AJAX servlet of kmelia answers the GET as the POST, and none of its URLs\u000aholds any of the keywords making the synchronizer token required on a GET. So\u000anone of its operations was protected, including the deletion of publications\u000awhich the report takes as protected: its URL does hold the delete keyword, but\u000athe rule applied to this servlet requires in addition the path to hold /jsp/,\u000awhich the path of a servlet doesn't.\u000a\u000aThe operations only reading something are now listed apart, every other one\u000abeing taken as writing something so that adding an operation doesn't expose it\u000aby mistake, and a writing operation requested by a GET is refused. That refusal\u000ais performed before the processing, whose catch-all would swallow it.\u000a\u000aThe user interface already submitted by POST the operations the report points\u000aat, as well as the deletion, the copy and the move of publications: what made\u000athe attack possible is the servlet accepting the GET. Three operations were\u000astill requested by a GET and are now submitted by POST: sorting the topics,\u000aemptying the trash from the basket, and binding a publication to another one.\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "217fe3edf581b66e5c9f935e9e367022e86977a6",
          "msg" : "Fix vulnerability #1464",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java",
            "kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java",
            "kmelia/kmelia-war/pom.xml"
          ],
          "commitId" : "b7db955aa0a1cdeaf903b52ddce739e32d3836fd",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Fix vulnerability #939\u000a\u000a(GitHub issue of Silverpeas-Components, reported against 6.4.6)\u000a\u000aUpdating a publication was granted against the component instance referred by\u000athe URL, whereas the publication to update was entirely defined by the request\u000abody, which carries both its identifier and its component instance. Any user\u000acould hence rewrite the metadata of any publication of the platform by referring\u000ait in the body, the identifiers being enumerable.\u000a\u000aThe publication is now refused when it doesn't belong to the instance the\u000aauthorization has been checked against. Note the report states a WRITER role is\u000arequired: it is not, the authorization of the REST framework only validating the\u000aaccess to the instance whatever the role played in it, so the exposure was wider\u000athan reported. Writing a publication, be it created or updated, now requires\u000athat role indeed.\u000a\u000aKmeliaResourceTest covers the checks. The war had no test at all, hence the\u000atest dependency added to its POM.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "b7db955aa0a1cdeaf903b52ddce739e32d3836fd",
          "msg" : "Fix vulnerability #939",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java"
            },
            {
              "editType" : "add",
              "file" : "kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java"
            },
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/pom.xml"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java",
            "delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java"
          ],
          "commitId" : "ce910d20953d1f7a5129974ec71e8dfabfe1f973",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Reserve the management of the delegated news to the managers\u000a\u000aModifying and deleting the delegated news is reserved to the managers of the\u000aapplication, as its user interface applies on its side. The REST service was\u000agranted against a mere access to the component instance, whatever the role\u000aplayed in it, so any of its users was able to reorder and to delete them by\u000arequesting it directly.\u000a\u000aFound while auditing the other REST resources against the flaw reported by the\u000aissue #939 of this repository.\u000a\u000aListDelegatedNewsResourceTest covers the check.\u000a\u000aCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "ce910d20953d1f7a5129974ec71e8dfabfe1f973",
          "msg" : "Reserve the management of the delegated news to the managers",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java"
            },
            {
              "editType" : "add",
              "file" : "delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java"
            }
          ]
        },
        {
          "_class" : "hudson.plugins.git.GitChangeSet",
          "affectedPaths" : [
            "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
          ],
          "commitId" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
          "timestamp" : 1790599054000,
          "author" : {
            "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
            "fullName" : "Miguel Moquillon"
          },
          "authorEmail" : "miguel.moquillon@gmail.com",
          "comment" : "Take into account sonarcloud feedback\u000a",
          "date" : "2026-09-28 14:37:34 +0200",
          "id" : "de9cf8606c9910989890a6d004cd47a8e2f611ca",
          "msg" : "Take into account sonarcloud feedback",
          "paths" : [
            {
              "editType" : "edit",
              "file" : "kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java"
            }
          ]
        }
      ],
      "kind" : "git"
    }
  ],
  "culprits" : [
    {
      "absoluteUrl" : "https://integration.silverpeas.org/jenkins/user/mmoquillon",
      "fullName" : "Miguel Moquillon"
    }
  ],
  "inProgress" : False,
  "nextBuild" : None,
  "previousBuild" : {
    "number" : 570,
    "url" : "https://integration.silverpeas.org/jenkins/job/Silverpeas_Stable_AutoDeploy/570/"
  }
}