SuffolkLITLab / FormFyxer

A tool for learning about and pre-processing forms
MIT License
11 stars 1 forks source link

Force reportlab to use latest security patch #105

Closed BryceStevenWilley closed 1 year ago

BryceStevenWilley commented 1 year ago

From the reportlab mailing list:

These fix a potential security vulnerability in the parsing of colours.
Previously, Iif someone had coded an application allowing user-input
expressions to be passed to our toColor constructor function, there was a
way to execute inappropriate code.  If you are doing this, please upgrade
to the newest version.

I don't think we use it, but better to be safe IMO.