As this header exposes some internal information like application name, port number and active profiles it should be enabled only on demand.
Comment From: tlefevre
Why was this closed? It seems like a legit concern. The presence of this header easily discloses that the application responding is a spring boot application.
Comment From: snicoll
@tlefevre this issue was closed in 2.0.0.M1
as implemented see 20f201b.
Comment From: tlefevre
Ah, my apologies!