Skip to content

unsafe_load ruleset for ruby #539

Open
@thypon

Description

Similarly to https://semgrep.dev/r?q=python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load YAML.load might be used to load ruby object. This is now allowlisted, but the old unsafe_load might still be called explicitly.

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions