aboutcode-org / aboutcode-org/scancode-toolkit
Reconsider `pickle` for caching purposes
- Lingua principale
- Python
- Stelle
- 2.6k
- Fork
- 791
- Merge medio
- 1g 12h
- PR unite (30g)
- 5
Descrizione
## Short Description
Currently, SCTK (and especially `licensedcode`/`licensedcode-index`) uses a cache file which is distributed on PyPI. This cache is being generated using the `pickle` module, which is usually discouraged for untrusted data, as it allows for executing arbitrary code (compared to "pure" data container formats like JSON etc.)
## Possible Labels
- new feature
## Select Category
- [x] Enhancement
- [ ] Add License/Copyright
- [ ] Scan Feature
- [ ] Packaging
- [ ] Documentation
- [ ] Expand Support
- [ ] Other
## **Describe the Update**
Use a cache container format which does not allow executing arbitrary code.
## **How This Feature will help you/your organization**
Reduce the risk of processing possibly untrusted data, regardless of the fact that using SCTK already requires a certain level of trust for SCTK itself.
## **Possible Solution/Implementation Details**
## **Example/Links if Any**
## **Can you help with this Feature**
There is more design needed and I do not have enough overview of the corresponding functionality to properly help with this.
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.