blakeNaccarato / copier-python

Copier template for Python projects
https://blakenaccarato.github.io/copier-python/
MIT License
4 stars 0 forks source link

Document how we safely handle CodeQL alert: Arbitrary file write during tarfile extraction #431

Open blakeNaccarato opened 2 months ago

blakeNaccarato commented 2 months ago

Please use this form appropriately

Please check that this internal matter hasn't already been raised

Description

See for instance:

We handle this safely by running the SHA-256 checksum before extracting, this should be documented in the template as it will fire off in repos using this template. Eventually, it may make sense to single-source this automatic Python installation script, or just wait for Charlie Marsh to do it over at uv 😅.