Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

fix(sec): set default maximum batching size to 500 to prevent Denial-of-Service #364

Open
hainenber wants to merge 2 commits intographql:main from
hainenber:secure-default-for-max-batch-size
Open

fix(sec): set default maximum batching size to 500 to prevent Denial-of-Service #364
hainenber wants to merge 2 commits intographql:main from
hainenber:secure-default-for-max-batch-size

Conversation

@hainenber
Copy link

@hainenber hainenber commented Oct 29, 2024
edited
Loading

A light attempt to resolve SNYK-JS-DATALOADER-8248488 by setting up a default maxBatchSize to be 500.

The limit is chosen arbitrarily along with inspiration from Elastic's Beats equivalent

... of Service
Signed-off-by: hainenber <dotronghai96@gmail.com>
Copy link

linux-foundation-easycla bot commented Oct 29, 2024
edited
Loading

CLA Signed

The committers listed above are authorized under a signed CLA.

Signed-off-by: hainenber <dotronghai96@gmail.com>
@hainenber hainenber changed the title (削除) fix(sec): set default maximum batching size to 1000 to prevent Denial-of-Service (削除ここまで) (追記) fix(sec): set default maximum batching size to 500 to prevent Denial-of-Service (追記ここまで) Oct 30, 2024
Copy link
Member

@saihaj saihaj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would consider this as a breaking change. We are changing a default limit and potentially for someone it can start breaking the CI if they don't adjust this limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

@saihaj saihaj saihaj requested changes

Requested changes must be addressed to merge this pull request.

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

Comments

AltStyle によって変換されたページ (->オリジナル) /