Apache Fesod (Incubating) 2.1.0-incubating Officially Released
October 2026 — The Apache Fesod (Incubating) community is pleased to announce the official release of Apache Fesod (Incubating) 2.1.0-incubating.
This release continues Fesod's steady evolution under the Apache Software Foundation (ASF) Incubator. With 110 pull requests merged by contributors from around the world, it delivers significant new capabilities for column-based reading and writing, enhanced Excel format compatibility, performance optimizations, and strengthened supply-chain security through fully reproducible builds.
Milestone Significance: From Compliance to Capability
After laying a solid compliance and governance foundation in the 2.0.x releases, version 2.1.0 marks Fesod's transition from "getting the house in order" to shipping meaningful new features at scale:
- 110 PRs Merged: Covering features, bug fixes, refactoring, documentation, testing, and build automation.
- 10 New Contributors from Four Countries: Hailing from China, Ireland, Latvia, and South Korea, this release's contributors reflect Fesod's growing international reach.
- Reproducible Builds: Fixed
project.build.outputTimestampguarantees byte-for-byte reproducible artifacts — a key supply-chain security improvement. - Security Hardening: Remote URL image access now requires an explicit allowlist, and multiple dependency vulnerabilities (XXE, CVE fixes) were resolved.
Key Highlights
1. New Features for Flexible Excel Processing
- Freeze Pane Support: Freeze rows and columns when writing via the
@FreezePaneannotation or a customWriteHandler. - Column-Based Reading for XLS and CSV: In addition to existing column-based reading for XLSX,
2.1.0extends column-level read control to legacy XLS and CSV files, letting you read only the columns you need. - Fluent Header API for No-Bean Mode: Build headers programmatically with a fluent API when you are not using annotated beans.
java.time.LocalTimeConverters: Native conversion support forLocalTimevalues in read and write paths.- Image Converter Refinement:
StringImageConverterwas split into dedicatedPathnameandBase64converters for clearer, safer image handling. - Performance: Date and number formatters are now cached to reduce repeated parsing overhead during large reads.
2. Security & Compliance
- Remote URL Image Allowlist:
readnow requires an explicit allowlist for remote URL images, mitigating SSRF-style risks. - Reproducible Builds: Fixed timestamps produce identical artifacts across builds, enabling community verification of published binaries.
- Incubating Compliance:
DISCLAIMERfiles are now bundled into both binary and sources JARs underMETA-INF. - Dependency Hardening: Upgraded
assertj-core(XXE fix),fastjson2,slf4j, and npm dependencies to resolve known vulnerabilities.
3. Stability & Robustness
- Legacy Format Fixes: XLS BIFF8 encryption is now correctly applied (previously broken by premature password clearing).
- Correct Date Handling: Fixed
java.sql.Date/Timehandling in CSV cells and1904windowing fallback for@DateTimeFormatdefaults. - Template Fill on Windows: Resolved fill-template copy failures on Windows platforms.
- Batch Read Integrity: Fixed
PageReadListenerduplicate rows when switching sheets, and copied sheet-level read parameters to sheet holders.
A Global Community
"Community Over Code" comes alive in the geography of this release. The 16 named contributors behind 2.1.0-incubating span four countries:
- China (13): Suzhou (3), Hangzhou (1), Tianjin (1), Beijing (1), and other cities (7).
- Ireland (1): Kilkenny.
- Latvia (1).
- South Korea (1).
From column-based reading to freeze panes, these features were shaped through international collaboration — code reviews, discussions, and testing carried out across time zones. This diversity is the engine driving Fesod's steady progress under the ASF Incubator.
Key Changes at a Glance
Features
- Added freeze pane support via
@FreezePaneorWriteHandler. - Added column-based reading for XLS and CSV files.
- Added fluent header API for no-bean mode.
- Split
StringImageConverterintoPathnameandBase64converters. - Added
java.time.LocalTimeconverters. - Added column index limit support in
ReadSheet. - Registered
EscapeHexCellWriteHandlerby default for XLSX.
Bugfixes
- Fixed XLS BIFF8 encryption not being applied.
- Fixed
CsvCellcrashes onjava.sql.Date/Timevalues. - Fixed
PageReadListenerduplicate rows between sheets. - Fixed Windows fill-template copy failures.
- Fixed
1904windowing fallback for@DateTimeFormatdefaults. - Fixed
_xHHHH_escape decoding in inline string cells.
Refactoring
- Unified and overloaded
readSheetmethods for flexible usage. - Replaced list-based column lookups with
ColumnIndexResolver. - Generated trivial accessors with Lombok.
- Removed the
fesod-examplesmodule.
For a detailed list of changes, please refer to the GitHub Release Notes and the full changelog.
Acknowledgments
"Community Over Code" is the core philosophy of the Apache Software Foundation. We would like to thank all the developers, mentors, and community members who contributed to this release.
New Contributors
We would like to extend a warm welcome and a special thank you to the 10 new members who made their first contribution in this release:
@32154678925, @skytin1004, @sapienza88, @Duansg, @nkuprins, @Aias00, @xleoken, @leehaut, @codeAnqiang-ma, @Mikkey-f
Special thanks to @alaahong, @delei, @psxjoy, @bengbengbalabalabeng, @nkuprins, @sapienza88, @GOODBOY008, @pjfanning, and everyone who submitted PRs and suggestions on GitHub. Your dedication to features, bug fixing, testing, and release management made this release possible.
How to Get Involved
You can download and experience the new Apache Fesod (Incubating) through the following channels:
- Official Website: https://fesod.apache.org/
- Source Code: https://github.com/apache/fesod
- Maven Central:
<dependency>
<groupId>org.apache.fesod</groupId>
<artifactId>fesod-sheet</artifactId>
<version>2.1.0-incubating</version>
</dependency>
Join Us!
The Apache Fesod (Incubating) community is always open to new contributors. You can reach out to us by subscribing to the mailing list at dev@fesod.apache.org or by submitting issues on GitHub.
We look forward to growing together within the Apache Incubator!