False positive: Python - Deserialization of user-controlled data
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
**Description of the false positive**
The `py/unsafe-deserialization` alerts on PyYaml's `yaml.load` when the provided `Loader` inherits from a safe loader (`yaml.loader.SafeLoader`).
**Code samples or links to source code**
https://github.com/blakeblackshear/frigate/blob/14c89c9b638bed90ef02e31beb20e84ab61dba8d/frigate/util/builtin.py#L87-L112
**URL to the alert on GitHub code scanning (optional)**
https://github.com/blakeblackshear/frigate/security/code-scanning/26
Contributor guide
Research direction
Review the linked frigate/util/builtin.py lines 87-112 and the py/unsafe-deserialization query to understand how the custom Loader is recognized. Confirm the query distinguishes loaders inheriting from yaml.loader.SafeLoader and verify that the linked code no longer produces a false-positive alert.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100