Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

gh-74453: Add stronger security warning to os.path.commonprefix#144401

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
sethmlarson wants to merge3 commits intopython:main
base:main
Choose a base branch
Loading
fromsethmlarson:os-path-commonprefix

Conversation

@sethmlarson
Copy link
Contributor

@sethmlarsonsethmlarson commentedFeb 2, 2026
edited by github-actionsbot
Loading

The first part of closing#74453, this documentation update I believe is less controversial than a deprecation. I'm recommending backporting this warning, as all Python versions supported today havecommonpath().

The mix-up thatcommonprefix is acceptable for generating a path prefix (versus a string prefix) occurred at least once in a critical packaging tool:https://www.cve.org/CVERecord?id=CVE-2026-1703 Given its usage (40K+ hits on GitHub) I suspect this is not the only occurrence.


📚 Documentation preview 📚:https://cpython-previews--144401.org.readthedocs.build/

@bedevere-appbedevere-appbot added docsDocumentation in the Doc dir skip news labelsFeb 2, 2026
@sethmlarsonsethmlarson added type-securityA security issue stdlibStandard Library Python modules in the Lib/ directory skip news and removed awaiting review skip news labelsFeb 2, 2026
Copy link
Member

@StanFromIrelandStanFromIreland left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

LGTM

(``''``).

..note::
..danger::
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

We do not often use "danger" but rather prefer using warning (I believe we have something about it in the devguide)

sethmlarson reacted with thumbs up emoji
Copy link
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Thanks! I've updated towarning instead ofdanger.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

I believe we have something about it in the devguide

Out of curiosity, which section? I was unable to find any on these.

Copy link
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Copy link
Member

@picnixzpicnixzFeb 2, 2026
edited
Loading

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Yes here. It is just so that we do not have a proliferation of different boxes (while Sphinx and docutils provide lots of boxes we tend to only use a few of them). In addition other security warnings were usually indicated through a warning.

Though if we actually use danger/important instead of warning, feel free to revert my suggestion (from what I remember we mostly used warning)

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@StanFromIrelandStanFromIrelandStanFromIreland approved these changes

@picnixzpicnixzpicnixz approved these changes

Assignees

No one assigned

Labels

awaiting mergedocsDocumentation in the Doc dirskip newsstdlibStandard Library Python modules in the Lib/ directorytype-securityA security issue

Projects

Status: Todo

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

3 participants

@sethmlarson@picnixz@StanFromIreland

[8]ページ先頭

©2009-2026 Movatter.jp