Skip to content

Commit

Permalink
yaml.load()をyaml.safe_load()に差し替え
Browse files Browse the repository at this point in the history
GitHubで CVE-2017-18342 のアラートが出ていた。
対応策として以下のissueがあった。

- yaml/pyyaml#193 (comment)
- yaml/pyyaml#207 (comment)

そのため、yaml.safe_load()へと差し替えた
  • Loading branch information
thinkAmi committed Feb 14, 2019
1 parent 56e0793 commit 2216fa9
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion apps/cultivar/apple.py
Expand Up @@ -10,7 +10,7 @@ def __init__(self):
def load_cultivars(self) -> dict:
""" プロジェクト直下にあるapples.yamlから品種名を取得する """
with open(os.path.join(settings.BASE_DIR, 'apples.yaml'), 'r', encoding='utf-8') as f:
cultivars = yaml.load(f)
cultivars = yaml.safe_load(f)
return cultivars

def get_color(self, cultivar: str) -> str:
Expand Down

0 comments on commit 2216fa9

Please sign in to comment.