Skip to content

patch ReDOS vulnerability in GaussianInput.from_string#4476

Merged
shyuep merged 1 commit intomaterialsproject:masterfrom
lbluque:master
Aug 13, 2025
Merged

patch ReDOS vulnerability in GaussianInput.from_string#4476
shyuep merged 1 commit intomaterialsproject:masterfrom
lbluque:master

Conversation

@lbluque
Copy link
Contributor

@lbluque lbluque commented Aug 12, 2025

Summary

Major changes:

Checklist

  • Google format doc strings added. Check with ruff.
  • Type annotations included. Check with mypy.
  • Tests added for new features/fixes.
  • If applicable, new classes/functions/modules have duecredit @due.dcite decorators to reference relevant papers by DOI (example)

Tip: Install pre-commit hooks to auto-check types and linting before every commit:

pip install -U pre-commit
pre-commit install

@lbluque
Copy link
Contributor Author

lbluque commented Aug 12, 2025

This has been around for a while, is there a reason this hasn't been patched that I missed?

@lbluque lbluque changed the title patch ReDOS vulnerability in GaussianInput.from_str patch ReDOS vulnerability in GaussianInput.from_string Aug 12, 2025
@shyuep shyuep merged commit 0f5c4af into materialsproject:master Aug 13, 2025
43 of 44 checks passed
@shyuep
Copy link
Member

shyuep commented Aug 13, 2025

Thanks!

@shyuep
Copy link
Member

shyuep commented Aug 13, 2025

No you didn’t miss anything. I guess mainly no one had the bandwidth to deal with it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants