You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PyYAML v3 has a high-severity security warning where yaml.load is unsafe. There has been an extensive discussion (summarised in their issue 207 ), but no resolution yet. It is expected that v5 will solve this, with a final release expected some time in march 2019.
In the mean time, we could document that this doesn't affect us (because we only dump YAML). Or just wait for a new version.
The text was updated successfully, but these errors were encountered:
garyd203
changed the title
Address or document PyYAML v3 CVE for unsafe yaml.load
Address or document PyYAML v3 CVE for unsafe yaml.load()
Mar 11, 2019
PyYAML v3 has a high-severity security warning where
yaml.load
is unsafe. There has been an extensive discussion (summarised in their issue 207 ), but no resolution yet. It is expected that v5 will solve this, with a final release expected some time in march 2019.In the mean time, we could document that this doesn't affect us (because we only dump YAML). Or just wait for a new version.
The text was updated successfully, but these errors were encountered: