-
Notifications
You must be signed in to change notification settings - Fork 62
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update RELEASE_NOTES.md for 0.12.0 release #285
Update RELEASE_NOTES.md for 0.12.0 release #285
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Need to change the version number and reword some things
RELEASE_NOTES.md
Outdated
@@ -1,3 +1,21 @@ | |||
### 0.11.3 January 12 2022 #### |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Version number should be 0.12.0
RELEASE_NOTES.md
Outdated
@@ -1,3 +1,21 @@ | |||
### 0.11.3 January 12 2022 #### | |||
|
|||
* Add deserialization whitelisting feature [#281](https://github.com/akkadotnet/Hyperion/pull/281) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'd reword this to "allow explicit control over which types can be deserialized" - and then I'd mention that it's recommended to use this feature as a best practice going forward because it can prevent https://cwe.mitre.org/data/definitions/502.html
I'll probably also need to add security notices for this repo too so that alert will get pushed out in the dependabot notifications for repos that have it enabled. I'll need to look into how to do that.
RELEASE_NOTES.md
Outdated
|
||
* Add deserialization whitelisting feature [#281](https://github.com/akkadotnet/Hyperion/pull/281) | ||
|
||
We've expanded our deserialization safety check to block dangerous types from being deserialized. You can now create a custom deserialize layer type filter programmatically: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This and the sample are good
RELEASE_NOTES.md
Outdated
var serializer = new Serializer(options); | ||
``` | ||
|
||
For complete documentation, please read the [readme on whitelisting types.](https://github.com/akkadotnet/Hyperion#whitelisting-types-on-deserialization) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Change the link text to say "readme on filtering types for secure deserialization"
…s/Hyperion into Update_RELEASE_NOTES_for_0.11.3
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
No description provided.