dssg / triage

General Purpose Risk Modeling and Prediction Toolkit for Policy and Social Good Problems
Other
187 stars 61 forks source link

Consider moving back to yaml.full_load for matrix metadata #839

Open shaycrk opened 3 years ago

shaycrk commented 3 years ago

See discussion associated with #835

We switched to yaml.load when upgrading pyYAML to 5.4; moving back to full_load would provide some security enhancements but require changing how we represent as_of_time and feature lists in a way that would break compatibility with matrices generated by previous versions of triage, so we should decide if the improvements outweigh that cost.