diff --git a/.gitattributes b/.gitattributes
new file mode 100644
index 0000000..1d51036
--- /dev/null
+++ b/.gitattributes
@@ -0,0 +1,17 @@
+# Normalise line endings for every text file in the repository.
+#
+# java-parent 1.3.0 configures Spotless with UNIX, which makes the
+# formatter's output independent of the developer's platform and Git configuration. That alone does
+# not make the published sources jar LF-clean — Git still checks files out according to the local
+# core.autocrlf — so the parent expects each child project to carry this file. Without it a build on
+# Windows produces a sources jar with CRLF and the release stops being byte-reproducible.
+* text=auto eol=lf
+
+# Binary files Git must never touch.
+*.jar binary
+*.png binary
+*.jpg binary
+*.jpeg binary
+*.gif binary
+*.ico binary
+*.pdf binary
diff --git a/docs/TODO.md b/docs/TODO.md
index d5f2bfc..9a23762 100644
--- a/docs/TODO.md
+++ b/docs/TODO.md
@@ -374,8 +374,11 @@ Micrometer into every consuming application now.
Spec 018 reads three files that no Open Elements build currently produces. The wiring is a
`java-parent` concern plus one line per application repository:
-- `project.build.outputTimestamp` fixed in `java-parent` — **in progress separately**; without it
- no Maven build in the org is byte-reproducible, independent of spec 018.
+- ~~`project.build.outputTimestamp` fixed in `java-parent`~~ — **done**: shipped in
+ `java-parent` 1.3.0 as the literal `2026-09-10T00:00:00Z`, and this reactor is on it. Verified by
+ building the reactor twice and comparing artifact checksums: byte-identical. The parent's comment
+ states it explicitly — the value is *not* a build time, it identifies the `java-parent` release an
+ artifact was built against; `release.sh` rewrites it per release.
- `spring-boot-maven-plugin:build-info` in `java-parent`'s `pluginManagement`, with
`additionalProperties` carrying `commit`, activated per application.
- `cyclonedx-maven-plugin` output redirected to
@@ -390,4 +393,6 @@ sit in an application-level activation, never in a profile shared with library m
trap that already forced `generateGitPropertiesFile=false` in `java-parent`'s `full-build` profile.
**Context:** Surfaced during the `/grill-me` for spec 018; deferred because `java-parent` is a
-separate repository and its `outputTimestamp` change is already being made in parallel.
+separate repository. Its `outputTimestamp` part has since landed (1.3.0, 2026-09-10); the remaining
+bullets — `build-info`, the SBOM output path and `ARG GIT_COMMIT` in the application Dockerfiles —
+are still open, and they are what spec 018 actually needs in order to read anything.
diff --git a/docs/specs/018-application-build-info/design.md b/docs/specs/018-application-build-info/design.md
index a57db5c..fe8c3f8 100644
--- a/docs/specs/018-application-build-info/design.md
+++ b/docs/specs/018-application-build-info/design.md
@@ -340,7 +340,7 @@ the model to be populated. It belongs in `java-parent` and in the application re
| Requirement | Where |
|---|---|
-| `project.build.outputTimestamp` set to a fixed value | `java-parent` (in progress, separately) |
+| `project.build.outputTimestamp` set to a fixed value | `java-parent` — **shipped in 1.3.0** (`2026-09-10T00:00:00Z`) |
| `spring-boot-maven-plugin:build-info` in `pluginManagement`, with `additionalProperties` carrying `commit` | `java-parent`, activated per application |
| `cyclonedx-maven-plugin` output to `${project.build.outputDirectory}/META-INF/sbom/application.cdx.json` | `java-parent`, activated per application |
| `ARG GIT_COMMIT` in the Dockerfile, passed to Maven | each application repository |
diff --git a/pom.xml b/pom.xml
index 45aadf9..45af940 100644
--- a/pom.xml
+++ b/pom.xml
@@ -5,7 +5,7 @@
com.open-elements
java-parent
- 1.2.1
+ 1.3.0
spring-services
@@ -51,12 +51,13 @@
spring-services-bom
-
+
1.45.3
- 2.2.29
- 1.0.0
- 2.0.5
3.10.0
0.18.3
diff --git a/spring-services-core/pom.xml b/spring-services-core/pom.xml
index 0936be8..e71de58 100644
--- a/spring-services-core/pom.xml
+++ b/spring-services-core/pom.xml
@@ -36,15 +36,15 @@
spring-boot-starter-oauth2-resource-server
+
io.swagger.core.v3
swagger-annotations-jakarta
- ${swagger-annotations-jakarta.version}
+
org.jspecify
jspecify
- ${jspecify.version}
- compile