As this header exposes some internal information like application name, port number and active profiles it should be enabled only on demand.

Comment From: tlefevre

Why was this closed? It seems like a legit concern. The presence of this header easily discloses that the application responding is a spring boot application.

Comment From: snicoll

@tlefevre this issue was closed in 2.0.0.M1 as implemented see 20f201b.

Comment From: tlefevre

Ah, my apologies!