ppkarwasz opened a new pull request, #781: URL: https://github.com/apache/commons-vfs/pull/781
> [!WARNING] > This PR was submitted automatically to smoke-test > [Apache Commons Secure XML](https://github.com/apache/commons-xml) > and has not yet been verified by a human. > It will stay a draft until a committer reviews it and marks it ready. Creates the document builder that parses `providers.xml` configuration files through `org.apache.commons:commons-secure-xml` (1.0.0-SNAPSHOT until its first release) in `commons-vfs2`. The secure factory enables XML secure processing and installs a non-removable entity-resolver floor: external DTD and entity lookups are resolved to empty content instead of being fetched, and internal entity expansion is bounded. Internal entities declared in a configuration file's own DTD subset still expand (`setExpandEntityReferences` stays on); only external content is affected. CI and CodeQL run with `-Puse-apache-snapshots` so the SNAPSHOT dependency resolves. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
