• Phillip Webb's avatar
    Remove node and recursive limits for YAML · 0d80f46c
    Phillip Webb authored
    Update `OriginTrackedYamlLoader` to remove node limits and recursive
    parsing restrictions. SnakeYAML 1.26 introduced these options in order
    to protect against the "billion laugh attacks" but since we consider
    `application.yml` files to be trusted, we don't need these restrictions.
    
    Fixes gh-23096
    0d80f46c
Name
Last commit
Last update
.github Loading commit data...
buildSrc Loading commit data...
ci Loading commit data...
eclipse Loading commit data...
git/hooks Loading commit data...
gradle/wrapper Loading commit data...
idea Loading commit data...
spring-boot-project Loading commit data...
spring-boot-tests Loading commit data...
src Loading commit data...
.editorconfig Loading commit data...
.gitignore Loading commit data...
CODE_OF_CONDUCT.adoc Loading commit data...
CONTRIBUTING.adoc Loading commit data...
LICENSE.txt Loading commit data...
README.adoc Loading commit data...
SUPPORT.adoc Loading commit data...
build.gradle Loading commit data...
gradle.properties Loading commit data...
gradlew Loading commit data...
gradlew.bat Loading commit data...
settings.gradle Loading commit data...