Skip to content

Commit d9f416f

Browse files
committed
Add news
1 parent e4b84f3 commit d9f416f

File tree

1 file changed

+19
-0
lines changed

1 file changed

+19
-0
lines changed

Diff for: news/5390-tarfile-extract-data

+19
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
### Enhancements
2+
3+
* Use `tarfile.TarFile.extract[all](filter='data')` for improved tarball extraction security (e.g., disallow paths outside of or linking outside of the destination, remove group & other write/executable permissions, etc.). (#5390)
4+
5+
### Bug fixes
6+
7+
* <news item>
8+
9+
### Deprecations
10+
11+
* <news item>
12+
13+
### Docs
14+
15+
* <news item>
16+
17+
### Other
18+
19+
* <news item>

0 commit comments

Comments
 (0)