github / github/codeql

False positive: Python - Deserialization of user-controlled data

Open
#14,685 0 comments 0 reactions 0 assignees View on GitHub
false-positive Python
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

The `py/unsafe-deserialization` alerts on PyYaml's `yaml.load` when the provided `Loader` inherits from a safe loader (`yaml.loader.SafeLoader`).

**Code samples or links to source code**

https://github.com/blakeblackshear/frigate/blob/14c89c9b638bed90ef02e31beb20e84ab61dba8d/frigate/util/builtin.py#L87-L112

**URL to the alert on GitHub code scanning (optional)**

https://github.com/blakeblackshear/frigate/security/code-scanning/26

Contributor guide

Open the contributing guide

Research direction

Review the linked frigate/util/builtin.py lines 87-112 and the py/unsafe-deserialization query to understand how the custom Loader is recognized. Confirm the query distinguishes loaders inheriting from yaml.loader.SafeLoader and verify that the linked code no longer produces a false-positive alert.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.