Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignore gitpython vulnerability #984

Merged
merged 1 commit into from
Dec 14, 2022
Merged

Ignore gitpython vulnerability #984

merged 1 commit into from
Dec 14, 2022

Conversation

SaptakS
Copy link
Contributor

@SaptakS SaptakS commented Dec 13, 2022

The vulnerability is in the git clone functionality, especially when the URL used to clone is a unsanitized code execution string. Since we are never using gitpython ourselves so we are not cloning any URL supplied from the user. Also, bandit mentioned in their project that they are not using the cloning functionality either (PyCQA/bandit#971 (comment)). So it's safe to ignore this vulnerability for us.

@chigby chigby merged commit c6b4cfe into develop Dec 14, 2022
@chigby chigby deleted the ignore-gitpython branch December 14, 2022 19:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants