We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 00a0b12 commit 3d3f4baCopy full SHA for 3d3f4ba
java/change-notes/2021-02-15-snakeyaml-fn-fix.md
@@ -0,0 +1,5 @@
1
+lgtm,codescanning
2
+* The query "Unsafe Deserialization" (`java/unsafe-deserialization`) has been
3
+ improved to report those cases where SnakeYaml `Constructor` is used to fix
4
+ the unmarshaled object graph root's type but injection is still possible in
5
+ nested nodes of the object graph.
0 commit comments