[
https://issues.apache.org/jira/browse/NIFI-2516?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15413511#comment-15413511
]
ASF GitHub Bot commented on NIFI-2516:
--------------------------------------
Github user brosander commented on the issue:
https://github.com/apache/nifi/pull/809
@pvillard31 I believe I've addressed your concerns, thanks for the feedback
> Extract version info into parent pom, upgrade to commons-io 2.5
> ---------------------------------------------------------------
>
> Key: NIFI-2516
> URL: https://issues.apache.org/jira/browse/NIFI-2516
> Project: Apache NiFi
> Issue Type: Sub-task
> Reporter: Bryan Rosander
> Assignee: Bryan Rosander
>
> Parent pom at root of nifi project should contain the dependency versions.
> commons-io 2.5 is required for its BoundedReader which facilitates putting a
> cap on the amount of bytes read during the payload deserialization. This is
> useful in avoiding an arbitrarily large payload sent by a malicious client.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)