[ https://issues.apache.org/jira/browse/DOXIA-716?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17801332#comment-17801332 ]
ASF GitHub Bot commented on DOXIA-716: -------------------------------------- michael-o commented on PR #187: URL: https://github.com/apache/maven-doxia/pull/187#issuecomment-1872514850 > looks good to me. While we are here maybe something for parsing and later for validation can be hardened: https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html This should be separate, please file a JIRA issue. > Update and unify XMLReader creation and configuration > ----------------------------------------------------- > > Key: DOXIA-716 > URL: https://issues.apache.org/jira/browse/DOXIA-716 > Project: Maven Doxia > Issue Type: Improvement > Components: Core > Affects Versions: 2.0.0-M8 > Reporter: Michael Osipov > Assignee: Michael Osipov > Priority: Major > Fix For: 2.0.0-M9 > > > * {{XMLReaderFactory}} is deprecated from Java 9 > * Force XML Schema as main language if both DTD and XSD are provided > * Force {{Locale#ROOT}} for portability > * Remove old Xerces hack -- This message was sent by Atlassian Jira (v8.20.10#820010)