Twenty-five years of Roller, and suddenly a backlog
It's crazy that I started working on a project called Roller twenty-five years ago this month, and next year Apache Roller will celebrate its 20th year as a top-level Apache project. Somehow I am still working in this same codebase.
Roller has been a pretty sleepy project for a long while, only making releases in response to incoming vulnerability reports or dependecy upgrades. But recently, there has been a resurgence in Roller development driven by artificial intelligence. In August and September, a handful of folks reported a total of 26 security vulnerabilities, all comprehensive with steps to reproduce and suggested fixes, and most were legit problems in Roller. (post edit: yes, I am implying these vulnerabilities were found by and reports written by AI)
The 2026 security batch, from first report to Apache Roller 6.1.6.
Around the same time, long-time Roller contributor Matt Raible made a series of AI-powered contributions, including a port of Roller from the old Java EE APIs to the Jakarta APIs and a bunch of other improvements. Suddenly, the sleepy little Roller project has an actual backlog!
Dealing with the 26 vulnerability reports was a serious project and I made the most of AI. Each report requires a tedious twenty-something-step process, so I developed a system for triaging the reports into separate directories and recording the status of each in a series of Markdown files and Obsidian Tasks. I encoded that into an AI "skill" called roller-security that can be used by Claude and Codex. I used that skill to walk me through the work, draft emails, and edit the web forms needed to request, edit and publish CVEs.
AI was helpful in dealing with the vulnerabilities, but we would have gotten nowhere without Roller contributors stepping up to help out. Thanks to Greg Huber, Matt Raible and Michael Bien for many PR reviews, testing release candidates and many contributions over the years! And, thanks to reporters meifukun, n0mi1k, m4dn355, Ivan Iushkevich (Steph) and 姬珏 (CyberLeo) for the research and for following the ASF process.
The security vulnerabilities are still trickling in, so you'll see a Roller 6.1.7 sometime soon, and later a Roller 7 release built on the Jakarta EE APIs.