use yaml.safe_{load,dump} functions
The yaml.load() function can run arbitrary code, the safe_load() variant only understands a safe subset of YAML which is enough for dak.
Showing
想要评论请 注册 或 登录
The yaml.load() function can run arbitrary code, the safe_load() variant only understands a safe subset of YAML which is enough for dak.