diff --git a/gradle/forbiddenApiFilters/main.txt b/gradle/forbiddenApiFilters/main.txt index 334e0d79822..bd66c74402a 100644 --- a/gradle/forbiddenApiFilters/main.txt +++ b/gradle/forbiddenApiFilters/main.txt @@ -50,3 +50,6 @@ java.lang.reflect.Field#setLong(java.lang.Object,long) java.lang.reflect.Field#setFloat(java.lang.Object,float) java.lang.reflect.Field#setDouble(java.lang.Object,double) java.lang.invoke.MethodHandles.Lookup#unreflectSetter(java.lang.reflect.Field) + +# avoid Java deserialization entrypoint - see warning in https://docs.oracle.com/en/java/javase/25/docs/api/java.base/java/io/ObjectInputStream.html +java.io.ObjectInputStream#readObject()