Files
codeql/python/change-notes/2021-10-26-ruamel.yaml-modeling.md
2021-10-26 17:48:10 +02:00

3 lines
231 B
Markdown

lgtm,codescanning
* Added modeling of the `ruamel.yaml` PyPI package, resulting in additional sinks for the _Deserializing untrusted input_ (`py/unsafe-deserialization`) query (since `ruamel.yaml.load` can lead to code execution).