ppkarwasz commented on PR #11250:
URL: https://github.com/apache/seatunnel/pull/11250#issuecomment-5087878905

   My 2 cents on this long discussion:
   
   - In practice, only Xerces-derived parsers register with `ServiceLoader` 
these days. Therefore using Xerces-specific properties and fail-closed if they 
are not recognized, is not a problem.
   - If you want a 100% guarantee that the configuration will succeed:
     - either call 
`SAXParserFactory.newInstance("com.sun.org.apache.xerces.internal.jaxp.SAXParserFactoryImpl",
 null)` and always use the internal JDK implementation,
     - or call `SAXReader.setEntityResolver` with an ignore-all or deny-all 
resolver. All implementations need to implement FSP + entity resolver.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to