Bump FreeMarker to 2.3.35 and fix the loadObjectClassesToMaps javadoc (#1176)
Two code scanning alerts on `master`.
### Alert 1297: FreeMarker 2.3.34 → 2.3.35 (CVE-2026-84939)
FreeMarker before 2.3.35 resolves a malformed locale identifier into a
path outside the template root. Trivy reports it on
`opt/opendj/lib/org.freemarker.freemarker.jar` of the image built from
`master` (`trivy-build-alpine`).
In OpenDJ it is not reachable: FreeMarker only renders OpenDJ's own
templates, in `DocGenerationHelper` (opendj-cli) and the doc maven
plugin, and nothing takes a locale from a client. The jar ships in
`lib/` all the same, so the alert stays open until the version moves.
commons made the same bump in OpenIdentityPlatform/commons#311.
All three `Configuration` instances are built with
`Configuration.DEFAULT_INCOMPATIBLE_IMPROVEMENTS`, a fixed constant, so
the template behaviour does not follow the library version.
### Alert 1281: `CompressedSchema.loadObjectClassesToMaps` javadoc
The javadoc listed a `sync` parameter the method does not have (left
over from #920) and documented `mappings` twice, with the encode and
decode maps the wrong way round.
### Not in this PR
- jackson 2.18.9 → 2.18.11 (alerts 1302, 1305–1308) and netty-handler
4.2.15 → 4.2.17+ (alert 1284) come from the commons parent
(`jackson.version`, `netty-bom`), so they belong in a commons change and
a `commons.version` bump.
- The `trivy-image-*` alerts are on the published 5.1.2 image; `master`
already carries the fixed versions (bc-fips 2.1.3, jackson 2.18.9,
postgresql 42.7.12, mssql-jdbc 13.4.0, a fresh base image). They close
with the next release.
### Testing
`mvn -pl opendj-cli,opendj-doc-maven-plugin -am package -DskipTests`
builds with 2.3.35. The documentation generation itself runs in CI.