On Wed, Sep 23, 2026, 1:57 AM Mark Thomas <[email protected]> wrote:

> Fatima,
>
> First things first. I have upgraded your Coverity access so you should
> be able to resolve issues yourself directly. Feel free to continue
> asking questions here for anything you'd like clarification on.
>

Thanks for trusting me with this. I'll add a brief explanation there for
the first few issues I mark for a particular CWE (maybe all of them if that
is alright).

There is a simpler argument for this. StoreConfig writes and parses
> configuration files. Configuration files are trusted. Therefore there is
> no XXE concern (or any other XML parsing security concern).
>
> I've marked this one as a false positive too.
>

Oh OK, I overthought it. I guess I just stepped into the world of
enterprise java security.

Thanks for your work on these.
>

No problem. It was interesting.

Best regards,
Fatima

Reply via email to