Commit b14702a
authored
[skip ci] Specify unserialize() in security policy (GH-22184)
unserialize() may not receive attacker-controlled inputs according to our
documentation. This is technically already included in the second bullet point,
but common enough to be spelled out.1 parent 7092ff5 commit b14702a
1 file changed
Lines changed: 2 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
| 37 | + | |
| 38 | + | |
37 | 39 | | |
38 | 40 | | |
39 | 41 | | |
| |||
0 commit comments