Conversation
PyYAML 4.x is "safe" by default and in that context safe means that arbitrary python objects are not okay. However, defined tags which are added by the running process are safe. This change updates gabbi so that if unsafe YAML is desired, the new "danger_load" function is used and expands the NanChecker related tests to reflect this different understanding of safe and unsafe. I suspect our tests were incorrect in the past.
Owner
Author
|
Don't intend to merge this yet, still trying to work out if it is right. "Safe" has changed. |
This reflects the behavior of "safe" that I've been able to deduce.
If danger_load doesn't exist then we are in an older version and we fall back to load (as the unsafe load). This makes it possible to use this same code to switch back and forth between PyYAML 3 and 4 and get different results.
Owner
Author
|
This is covered by #267 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PyYAML 4.x is "safe" by default and in that context safe
means that arbitrary python objects are not okay. However,
defined tags which are added by the running process are
safe.
This change updates gabbi so that if unsafe YAML is desired,
the new "danger_load" function is used and expands the
NanChecker related tests to reflect this different
understanding of safe and unsafe. I suspect our tests
were incorrect in the past.