Hello , a'm paul
I noticed that the application configuration exposes all Spring Boot Actuator endpoints:
management.endpoints.web.exposure.include=*
Exposing all endpoints may unintentionally reveal sensitive internal information such as environment variables, metrics, logs, or bean configurations, especially in production environments.
I would like to propose limiting exposed endpoints to only the necessary ones (e.g., health and info) to improve security and follow Spring Boot best practices.
Please let me know if I can proceed with this improvement. Thank you!
Hello , a'm paul
I noticed that the application configuration exposes all Spring Boot Actuator endpoints:
Exposing all endpoints may unintentionally reveal sensitive internal information such as environment variables, metrics, logs, or bean configurations, especially in production environments.
I would like to propose limiting exposed endpoints to only the necessary ones (e.g., health and info) to improve security and follow Spring Boot best practices.
Please let me know if I can proceed with this improvement. Thank you!