Blogging Roller

Dave Johnson on open web technologies, social software and software development

Twenty-five years of Roller, and suddenly a backlog

It's crazy that I started working on a project called Roller twenty-five years ago this month, and next year Apache Roller will celebrate its 20th year as a top-level Apache project. Somehow I am still working in this same codebase.

Roller has been a pretty sleepy project for a long while, only making releases in response to incoming vulnerability reports or dependecy upgrades. But recently, there has been a resurgence in Roller development driven by artificial intelligence. In August and September, a handful of folks reported a total of 26 security vulnerabilities, all comprehensive with steps to reproduce and suggested fixes, and most were legit problems in Roller. (post edit: yes, I am implying these vulnerabilities were found by and reports written by AI)

Infographic: Apache Roller 2026 security batch. 26 vulnerability reports from 5 independent researchers in 42 days led to 18 CVEs fixed and disclosed in Roller 6.1.6, 52 days from first report to release. Of the 26 reports, 18 were accepted, 5 were duplicates and 3 were rejected. Severity of the 18 CVEs: 1 critical, 8 important, 9 moderate. 21 pull requests were merged over Labor Day weekend, 3 risky features were removed instead of patched, and there were 4 release candidates before the final vote. Timeline: first report Aug 3, PRs merged Sep 5 to 7, last report Sep 13, release and advisories Sep 24 to 25.
The 2026 security batch, from first report to Apache Roller 6.1.6.

Around the same time, long-time Roller contributor Matt Raible made a series of AI-powered contributions, including a port of Roller from the old Java EE APIs to the Jakarta APIs and a bunch of other improvements. Suddenly, the sleepy little Roller project has an actual backlog!

Dealing with the 26 vulnerability reports was a serious project and I made the most of AI. Each report requires a tedious twenty-something-step process, so I developed a system for triaging the reports into separate directories and recording the status of each in a series of Markdown files and Obsidian Tasks. I encoded that into an AI "skill" called roller-security that can be used by Claude and Codex. I used that skill to walk me through the work, draft emails, and edit the web forms needed to request, edit and publish CVEs.

AI was helpful in dealing with the vulnerabilities, but we would have gotten nowhere without Roller contributors stepping up to help out. Thanks to Greg Huber, Matt Raible and Michael Bien for many PR reviews, testing release candidates and many contributions over the years! And, thanks to reporters meifukun, n0mi1k, m4dn355, Ivan Iushkevich (Steph) and  姬珏 (CyberLeo) for the research and for following the ASF process.

The security vulnerabilities are still trickling in, so you'll see a Roller 6.1.7 sometime soon, and later a Roller 7 release built on the Jakarta EE APIs.

Dave Johnson in Roller • 🕒 05:35PM Sep 28, 2026
Comments:

Post a Comment:
  • HTML Syntax: NOT allowed