summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorTomáš Levora <t.levora@partner.samsung.com>2019-06-05 12:53:05 +0200
committerTomáš Levora <t.levora@partner.samsung.com>2019-06-05 11:31:42 +0000
commitfd0052218c0932ba6511bc6aa99f538ab03dd1c6 (patch)
tree99c2560de80190d8d97c1f6b236a83937c8dfe4b
parent16294b10526ff85f0701cdfd5a8238fbbbd314f4 (diff)
Fix issue with yaml.load in docker collector
docker-images-collector.sh script uses yaml.load python function in deprecated way and it is a potential security risk https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation Issue-ID: OOM-1897 Change-Id: Ie30e60b4ede2c87a02b7bbe76e0695f91dc207c6 Signed-off-by: Tomáš Levora <t.levora@partner.samsung.com>
-rwxr-xr-xbuild/creating_data/docker-images-collector.sh2
1 files changed, 1 insertions, 1 deletions
diff --git a/build/creating_data/docker-images-collector.sh b/build/creating_data/docker-images-collector.sh
index 9206b0bb..6761c328 100755
--- a/build/creating_data/docker-images-collector.sh
+++ b/build/creating_data/docker-images-collector.sh
@@ -47,7 +47,7 @@ import yaml
import sys
with open("${1}", 'r') as f:
- values = yaml.load(f)
+ values = yaml.load(f, Loader=yaml.SafeLoader)
enabled = filter(lambda x: values[x].get('enabled', False) == True, values)
print(' '.join(enabled))