Skip to content

Expand UNSAFE_IMPORTS blocklist (GHSA-m6fh-58r7-x697)#272

Merged
thomas-chauchefoin-tob merged 1 commit into
masterfrom
fix/GHSA-m6fh-58r7-x697
May 6, 2026
Merged

Expand UNSAFE_IMPORTS blocklist (GHSA-m6fh-58r7-x697)#272
thomas-chauchefoin-tob merged 1 commit into
masterfrom
fix/GHSA-m6fh-58r7-x697

Conversation

@thomas-chauchefoin-tob
Copy link
Copy Markdown
Collaborator

This blocks a direct command execution gadget with _posixsubprocess, a way to load local PTH with site, and potential exit hooks with atexit. Thanks to @reapermunky for the report!

This blocks a direct command execution gadget with `_posixsubprocess`,
a way to load local PTH with `site`, and potential exit hooks with
`atexit`.
@thomas-chauchefoin-tob thomas-chauchefoin-tob self-assigned this May 6, 2026
@thomas-chauchefoin-tob thomas-chauchefoin-tob merged commit e840861 into master May 6, 2026
12 checks passed
@thomas-chauchefoin-tob thomas-chauchefoin-tob deleted the fix/GHSA-m6fh-58r7-x697 branch May 6, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant