Andi Huber created CAUSEWAY-3550:
------------------------------------

             Summary: YamlUtils: Global tag expression is discouraged
                 Key: CAUSEWAY-3550
                 URL: https://issues.apache.org/jira/browse/CAUSEWAY-3550
             Project: Causeway
          Issue Type: Improvement
            Reporter: Andi Huber
            Assignee: Andi Huber
             Fix For: 2.0.0-RC3


YAML file first line historically was starting with a global tag pointing to 
the dto class. Yet this should no longer be used since SnakeYaml 2.0.

https://medium.com/@snyksec/snakeyaml-2-0-solving-the-unsafe-deserialization-vulnerability-c29a0f08f152



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to