Using spring.config.import could mean that files are accidentally exposed. It would be nice if an allowlist could be used to limit the locations that can be used.