We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
See https://bandit.readthedocs.io/en/1.7.8/plugins/b202_tarfile_unsafe_members.html
The text was updated successfully, but these errors were encountered:
One simple fix starting with Python 3.12 would be to use the extraction filter "data". This will be the default in Python 3.14.
The question is whether we need to make it configurable or not. Do we have legitimate use case of a different extraction filter?
See https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter
Sorry, something went wrong.
I have a testcase which reproduces the issue. Working on a fix.
grouigrokon
No branches or pull requests
See https://bandit.readthedocs.io/en/1.7.8/plugins/b202_tarfile_unsafe_members.html
The text was updated successfully, but these errors were encountered: