Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork33.7k
gh-102950: Implement PEP 706 – Filter for tarfile.extractall#102953
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Uh oh!
There was an error while loading.Please reload this page.
Changes from1 commit
cde089c2395c92561a9d454b56447867fc3734190dd55ae42c795bb35d850cc81e9050de11090b0c06743796fdf08ab5510474842a255634File filter
Filter by extension
Conversations
Uh oh!
There was an error while loading.Please reload this page.
Jump to
Uh oh!
There was an error while loading.Please reload this page.
Diff view
Diff view
Thanks to Ethan for spotting these
- Loading branch information
Uh oh!
There was an error while loading.Please reload this page.
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -38,7 +38,7 @@ Some facts and figures: | ||
| .. versionchanged:: 3.12 | ||
| Archives are extracted using a :ref:`filter <tarfile-extraction-filter>`, | ||
| which makesiteasy to either limit surprising/dangerous features, | ||
encukou marked this conversation as resolved. OutdatedShow resolvedHide resolvedUh oh!There was an error while loading.Please reload this page. | ||
| or to acknowledge that they are expected and the archive is fully trusted. | ||
| By default, archives are fully trusted, but this default is deprecated | ||
gpshead marked this conversation as resolved. Show resolvedHide resolvedUh oh!There was an error while loading.Please reload this page. | ||
| and slated to change in Python 3.14. | ||
| @@ -985,8 +985,8 @@ Here is an incomplete list of things to consider: | ||
| etc.). | ||
| * Check that filenames have expected extensions (discouraging files that | ||
| execute when you “click on them”, or extension-less files like Windows special device names), | ||
encukou marked this conversation as resolved. OutdatedShow resolvedHide resolvedUh oh!There was an error while loading.Please reload this page. | ||
| *Limit the number of extracted files, total size of extracted data, | ||
| filename length (including symlink length),andsize of individual files. | ||
| * Check for files that would be shadowed on case-insensitive filesystems. | ||
| Also note that: | ||