fix: semgrep rule for deprecated DefaultHttpClient-297 #12315
+13
−1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
### What
Fixes a Semgrep rule related to the deprecated
DefaultHttpClientusage.### Why
DefaultHttpClientis deprecated and does not support TLS 1.2, which makes it a security risk.The existing rule incorrectly flagged usage in
DefaultHttpClientBuilder, which already relies onHttpClientBuilder.This update corrects the rule to avoid false positives and improve scan accuracy.
### Details
http-client/src/main/java/io/micronaut/http/client/netty/DefaultHttpClientBuilder.java### Tests
### Notes
This is a rule-level correction only and does not introduce any functional or API changes.