Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
script: Change insecure mktemp to NamedTemporaryFile (#3444)
Deprecated mktemp function returns an arbitrary file name to use for a temporary file. However, the application does not immediately create/open this file. This introduces an opportunity for an attacker to interfere with the file to be created. Documentation on tempfile recommends replacing mktemp with NamedTemporaryFile. By doing this, there is no window between getting the temp file name and opening it.
- Loading branch information