coheigea opened a new pull request, #285: URL: https://github.com/apache/cxf-build-utils/pull/285
The mojo followed symbolic links in the scanned resource directories, so a link named *.xml could pull a file from anywhere on the build host into the generated artifact as a .fixml resource. When a resource targetPath was configured it was joined to the output directory without validation, so a "../" value wrote outside of it, and the .xml to .fixml rename was dropped, writing FastInfoset content under the original .xml name. Fail the build if a source file resolves to a location outside of its resource directory, or if a destination resolves outside of the output directory, and keep the .fixml extension when a targetPath is set. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
