Re: [PHP-DEV] PR: Bump libxml version, deprecate libxml_disable_entity_loader()

2020-07-31 Thread Benjamin Eberlei
Hi Dik, your e-mail has likely been going to spam for many subscribers of the mailing list, I have just seen it after reading Nikitas comment on the PR. https://github.com/php/php-src/pull/5867 I am all for this and wanted to bump the thread to the list so that everyone can see this as well. Ar

[PHP-DEV] PR: Bump libxml version, deprecate libxml_disable_entity_loader()

2020-07-16 Thread Dik Takken
Hi internals, I prepared a PR which aims to properly fix a long standing problem related to secure XML processing in PHP. In short, it bumps the minimum required version of libxml and it deprecates the libxml_disable_entity_loader() function. You can find the details in the PR: https://github.c