I expect
Security considerations for OAS and json schema.
They must clarify that referenced resources are usually dereferenced, and that related risks should be assessed, including:
- retrieval of non https resources
- loops and cycles
- ...
Is there something already baked on that ?
@jdesrosiers @darrelmiller