semgrep/semgrep-rules

java/jax-rs/security/insecure-resteasy.yaml no longer relevant?

JLLeitschuh opened this issue · 0 comments

Describe the bug

Reading through the documentation for SerializableProvider it seems that this functionality was disabled by default.

https://docs.jboss.org/resteasy/docs/3.9.1.Final/javadocs/org/jboss/resteasy/plugins/providers/SerializableProvider.html

Given this, is this rule no longer relevant and worth keeping in the default query set?

Priority
How important is this to you?

  • P0: blocking me from making progress
  • P1: this will block me in the near future
  • P2: annoying but not blocking me