Files
codeql/java/old-change-notes/2021-02-15-snakeyaml-fn-fix.md
Dave Bartolomeo fa40d59332 Move older change notes to old-change-notes
Now that change notes are per-package, new change notes should be created in the `change-notes` folder under the affected pack (e.g., `cpp/ql/src/change-notes` for C++ query change notes. I've moved all of the change note files that were added before we started publishing them in packs to an `old-change-notes` directory under each language, to reduce the temptation to add new change notes there.

I'm working on a document to describe how and when to create change notes for packs separately.
2021-12-14 12:35:04 -05:00

288 B

lgtm,codescanning

  • The query "Unsafe Deserialization" (java/unsafe-deserialization) has been improved to report those cases where SnakeYaml Constructor is used to fix the unmarshaled object graph root's type but injection is still possible in nested nodes of the object graph.