aboutcode-org / aboutcode-org/scancode-toolkit

Reconsider `pickle` for caching purposes

Aperta
#5,054 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
new feature
Lingua principale
Python
Stelle
2.6k
Fork
791
Merge medio
1g 12h
PR unite (30g)
5

Descrizione

## Short Description

Currently, SCTK (and especially `licensedcode`/`licensedcode-index`) uses a cache file which is distributed on PyPI. This cache is being generated using the `pickle` module, which is usually discouraged for untrusted data, as it allows for executing arbitrary code (compared to "pure" data container formats like JSON etc.)

## Possible Labels

- new feature

## Select Category

- [x] Enhancement
- [ ] Add License/Copyright
- [ ] Scan Feature
- [ ] Packaging
- [ ] Documentation
- [ ] Expand Support
- [ ] Other

## **Describe the Update**

Use a cache container format which does not allow executing arbitrary code.

## **How This Feature will help you/your organization**

Reduce the risk of processing possibly untrusted data, regardless of the fact that using SCTK already requires a certain level of trust for SCTK itself.

## **Possible Solution/Implementation Details**

## **Example/Links if Any**

## **Can you help with this Feature**

There is more design needed and I do not have enough overview of the corresponding functionality to properly help with this.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.