potiuk commented on PR #3966:
URL: https://github.com/apache/jena/pull/3966#issuecomment-4618369055

   Thanks @rvesse — genuinely useful, detailed review. Understood you're 
holding your own commits so the rest of the PMC can review the as-is draft 
first, so I won't push anything over that.
   
   For when you're ready: I've staged a revision incorporating all your 
suggestions — SSRF via `SERVICE` documented as a VALID vector (with the "no 
allow-list today" note), `FROM`/`file:` reworded as 
dataset-implementation-dependent (TDB2 restricts to dataset graphs), the 
"super-linear" DoS framing removed (operator-tuned, affects all compliant 
engines), the ARQ-JS (opt-in + eval-blacklisted) vs Java-custom-function 
(operator-classpath, by-design) distinction, and the TDB-FAQ resource 
references. It's ready to land whenever the PMC's done with the as-is draft — 
just say the word. (And afs@ can confirm the RDF/XML XXE-default question when 
convenient — that's the one item I left open.) No rush.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to