Files
codeql/python/change-notes/2021-10-26-ruamel.yaml-modeling.md
2021-10-26 17:48:10 +02:00

231 B

lgtm,codescanning

  • Added modeling of the ruamel.yaml PyPI package, resulting in additional sinks for the Deserializing untrusted input (py/unsafe-deserialization) query (since ruamel.yaml.load can lead to code execution).