oscerd commented on code in PR #26896: URL: https://github.com/apache/camel/pull/26896#discussion_r4121094388
########## docs/user-manual/modules/ROOT/pages/security-model.adoc: ########## @@ -923,7 +923,11 @@ be closed as `not a vulnerability`. `circuitBreaker`, `resilience4j`, JVM heap limits, and the relevant component-level options. Algorithmic-complexity attacks in third-party libraries are reported to the upstream project unless Camel exposes the - parser in a way that bypasses the library's own limits. + parser in a way that bypasses the library's own limits. A resource limit + that Camel itself offers, such as `maxDecompressedSize` on the Zip File and + Tar File data formats, is defence in depth for a property the framework + does not claim: a defect that stops it enforcing its documented value is a + bug, fixed as `VALID-HARDENING` rather than published as a CVE. Review Comment: Good catch — done in c596856. Extended the `VALID-HARDENING` row in the dispositions table so it matches this entry: its Meaning now also covers "a resource limit Camel itself offers for a property it does not claim (such as `maxDecompressedSize`) fails to enforce its documented value", and its "Licensed by" now cites _Out of scope_ alongside _Known limitations_ and _Guidance for component authors and reviewers_. Table and entry now agree. _Claude Code on behalf of oscerd_ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
