python execute security
- Dominant language
- TypeScript
- Stars
- 384
- Forks
- 58
- PR merge metrics
- No merged PRs in 30d
Description
Python execute has been disabled for the time being.
Since python is a general purpose language getting security right is trick, the way it currently runs it would be possible to grab some aws credentials, as well as other things like crypto mining, the 30s execute limit does help but does not fix the problem.
Much more robust tracing and limits are needed before enabling this feature again.
Contributor guide
Research direction
The issue names no files, tests, or entry points. Start by locating the disabled Python execution path and its existing 30-second limit. Done requires a documented tracing and limits design that addresses credential access and crypto-mining risks before execution is re-enabled.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100