potiuk commented on PR #3966: URL: https://github.com/apache/jena/pull/3966#issuecomment-4618369055
Thanks @rvesse — genuinely useful, detailed review. Understood you're holding your own commits so the rest of the PMC can review the as-is draft first, so I won't push anything over that. For when you're ready: I've staged a revision incorporating all your suggestions — SSRF via `SERVICE` documented as a VALID vector (with the "no allow-list today" note), `FROM`/`file:` reworded as dataset-implementation-dependent (TDB2 restricts to dataset graphs), the "super-linear" DoS framing removed (operator-tuned, affects all compliant engines), the ARQ-JS (opt-in + eval-blacklisted) vs Java-custom-function (operator-classpath, by-design) distinction, and the TDB-FAQ resource references. It's ready to land whenever the PMC's done with the as-is draft — just say the word. (And afs@ can confirm the RDF/XML XXE-default question when convenient — that's the one item I left open.) No rush. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
