This is an automated email from the ASF dual-hosted git repository.

afs pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/jena.git

commit 071880ac72efa24526370cb7f84acb1727b688af
Author: Andy Seaborne <[email protected]>
AuthorDate: Mon Aug 17 13:59:41 2026 +0100

    GH-4150: THREAT Model: Remove jena-shex as network reachable; note no 
imports for SHACL
---
 THREAT_MODEL.md | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/THREAT_MODEL.md b/THREAT_MODEL.md
index 150f42c601..2b304268a9 100644
--- a/THREAT_MODEL.md
+++ b/THREAT_MODEL.md
@@ -47,7 +47,7 @@ limitations under the License.
 | Stores + text index | `jena-tdb1`, `jena-tdb2`; **`jena-text` (Lucene)** | 
filesystem | **In.** On-disk store is operator-trusted and private to the 
owning process *(maintainer)*; the Lucene text index is reachable from SPARQL 
via `text:query` — an in-model query surface *(maintainer — afs flagged 
jena-text)* |
 | IRI / langtag | `jena-iri3986`, `jena-langtag`, `jena-base` | none | **In 
(input parsing)** *(inferred)* |
 | Extensions | `jena-geosparql`, `jena-serviceenhancer` | SERVICE | **In 
(reachable from queries)** *(inferred)* |
-| Validations | `jena-shacl`, `jena-shex` | HTTP GET requests (imports) | **In 
(import-fetch = SSRF surface)** *(maintainer — afs)* |
+| Validations | `jena-shacl` | HTTP GET requests | **In (no imports)** 
*(maintainer — afs)* |
 | Client/API helpers | `jena-rdfconnection`, `jena-querybuilder`, 
`jena-rdfpatch`, `jena-commonsrdf`, `jena-ontapi` | none | **In as libraries 
(memory/correctness)** *(inferred)* |
 | CLI tools | `jena-cmds` | filesystem | **In iff fed untrusted input; usually 
operator-run** *(inferred)* |
 | Examples / tests / benchmarks | `jena-examples`, `jena-integration-tests`, 
`jena-benchmarks` | n/a | **Out** *(see §3)* |

Reply via email to