aboutcode-org / aboutcode-org/scancode-toolkit

Reconsider `pickle` for caching purposes

Abierto
#5,054 0 comentarios 0 reacciones 0 asignados Ver en GitHub
new feature
Lenguaje dominante
Python
Estrellas
2.6k
Forks
791
Merge medio
1 d 12 h
PR fusionados (30 d)
5

Descripción

## Short Description

Currently, SCTK (and especially `licensedcode`/`licensedcode-index`) uses a cache file which is distributed on PyPI. This cache is being generated using the `pickle` module, which is usually discouraged for untrusted data, as it allows for executing arbitrary code (compared to "pure" data container formats like JSON etc.)

## Possible Labels

- new feature

## Select Category

- [x] Enhancement
- [ ] Add License/Copyright
- [ ] Scan Feature
- [ ] Packaging
- [ ] Documentation
- [ ] Expand Support
- [ ] Other

## **Describe the Update**

Use a cache container format which does not allow executing arbitrary code.

## **How This Feature will help you/your organization**

Reduce the risk of processing possibly untrusted data, regardless of the fact that using SCTK already requires a certain level of trust for SCTK itself.

## **Possible Solution/Implementation Details**

## **Example/Links if Any**

## **Can you help with this Feature**

There is more design needed and I do not have enough overview of the corresponding functionality to properly help with this.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.