Files
codeql/java/change-notes/2021-05-17-add-unsafe-deserialization-sinks.md
2021-05-17 18:49:16 +08:00

4 lines
203 B
Markdown

lgtm,codescanning
* The "Deserialization of user-controlled data" (`java/unsafe-deserialization`) query
now recognizes `JYaml`, `JsonIO`, `YAMLBeans`, `Castor`, `Hessian` and `Burlap` deserialization.