Skip to content

Commit 9356058

Browse files
committed
doc: add release note about XML parsing enhancements
1 parent b0ea5e5 commit 9356058

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,6 +77,8 @@ mvn spotless:check
7777
- (none)
7878

7979
#### 🏹 BUG FIXES
80+
- Make Service Provider XML parsing more secure and avoid XXEs (activate STaX2 security features)
81+
- Make Service Provider XML parsing thread-safe (use thread-local variants of XmlInputFactory)
8082
- Switch to Sonatype Central Portal to [replace sunset OSSRH](https://central.sonatype.org/pages/ossrh-eol/)
8183
- Upgrade [GDCC Maven Parent POM](https://github.com/gdcc/maven-parent) to 0.12.4 (includes some dependency updates, including security)
8284

0 commit comments

Comments
 (0)