[ 
https://issues.apache.org/jira/browse/NIFI-2516?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15413511#comment-15413511
 ] 

ASF GitHub Bot commented on NIFI-2516:
--------------------------------------

Github user brosander commented on the issue:

    https://github.com/apache/nifi/pull/809
  
    @pvillard31 I believe I've addressed your concerns, thanks for the feedback


> Extract version info into parent pom, upgrade to commons-io 2.5
> ---------------------------------------------------------------
>
>                 Key: NIFI-2516
>                 URL: https://issues.apache.org/jira/browse/NIFI-2516
>             Project: Apache NiFi
>          Issue Type: Sub-task
>            Reporter: Bryan Rosander
>            Assignee: Bryan Rosander
>
> Parent pom at root of nifi project should contain the dependency versions.
> commons-io 2.5 is required for its BoundedReader which facilitates putting a 
> cap on the amount of bytes read during the payload deserialization.  This is 
> useful in avoiding an arbitrarily large payload sent by a malicious client.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to