Hi Arnout, hi Mukul, Thank you very much for the patch :-)
I'm worried these changes will just be overwritten when we publish the site for the upcoming 2.7.3 version. The changes should be done to the site sources in the got repo. Mukul, Can you point Arnout to the right place in git? TY both! Gary On Thu, Jan 19, 2023, 04:27 Arnout Engelen <enge...@apache.org> wrote: > Hello, > > It seems people occasionally don't realize they should expect to take > some precautions before using Xalan on untrusted input. It might be > good to make an explicit note about that on the website, something > like the attached patch? > > Of course it would be even better if we could provide (or link to) > in-depth instructions, but until we have something like that I think > just highlighting the fact that this needs people's attention would be > an improvement. > > The patch is against https://svn.apache.org/repos/asf/xalan/site/ . I > also took the opportunity of updating some links to https. > > > Kind regards, > > Arnout > > --------------------------------------------------------------------- > To unsubscribe, e-mail: dev-unsubscr...@xalan.apache.org > For additional commands, e-mail: dev-h...@xalan.apache.org