diff options
author | Tomáš Levora <t.levora@partner.samsung.com> | 2019-06-05 12:53:05 +0200 |
---|---|---|
committer | Tomáš Levora <t.levora@partner.samsung.com> | 2019-06-05 11:31:42 +0000 |
commit | fd0052218c0932ba6511bc6aa99f538ab03dd1c6 (patch) | |
tree | 99c2560de80190d8d97c1f6b236a83937c8dfe4b | |
parent | 16294b10526ff85f0701cdfd5a8238fbbbd314f4 (diff) |
Fix issue with yaml.load in docker collector
docker-images-collector.sh script uses yaml.load python function in
deprecated way and it is a potential security risk
https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation
Issue-ID: OOM-1897
Change-Id: Ie30e60b4ede2c87a02b7bbe76e0695f91dc207c6
Signed-off-by: Tomáš Levora <t.levora@partner.samsung.com>
-rwxr-xr-x | build/creating_data/docker-images-collector.sh | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/build/creating_data/docker-images-collector.sh b/build/creating_data/docker-images-collector.sh index 9206b0bb..6761c328 100755 --- a/build/creating_data/docker-images-collector.sh +++ b/build/creating_data/docker-images-collector.sh @@ -47,7 +47,7 @@ import yaml import sys with open("${1}", 'r') as f: - values = yaml.load(f) + values = yaml.load(f, Loader=yaml.SafeLoader) enabled = filter(lambda x: values[x].get('enabled', False) == True, values) print(' '.join(enabled)) |