DiffSK / configobj

Python 3+ compatible port of the configobj library
https://configobj.readthedocs.org
Other
322 stars 76 forks source link

Vulnerable regex detected by Snyk. Please fix or avoid regex #240

Closed wannfq closed 2 months ago

wannfq commented 1 year ago

https://github.com/DiffSK/configobj/blob/e2ba4457c4651fa54f8d59d8dcdd3da950e956b8/src/configobj/validate.py#L534

wannfq commented 1 year ago

Ref: https://learn.snyk.io/lesson/redos/?_gl=1*1w34pg6*_ga*NzgwNjYzODE3LjE2OTE2NDQ3MDc.*_ga_X9SH3KP7B4*MTY5MjE4NTc5OS4yMS4xLjE2OTIxODU4NjEuMC4wLjA.

IloBe commented 1 year ago

Additional info:

thebaptiste commented 1 year ago

Maintainers seem to be in long holidays, ill, retired or dead... See PR #236 opened by @cdcadman since May 17 on this subject.

jelmer commented 2 months ago

236 is now merged, closing this.

aarondawg14 commented 2 months ago

@jelmer Has this been released yet?

jelmer commented 2 months ago

@aarondawg14 no, see the discussion on #237