New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use xml.etree through defusedxml #19640

Merged
merged 1 commit into from Dec 29, 2018

Conversation

Projects
None yet
3 participants
@scop
Copy link
Contributor

scop commented Dec 29, 2018

Description:

...for security reasons. Untested apart from tox/Travis, I don't have these devices around.

Related issue (if applicable): fixes #

Pull request in home-assistant.io with documentation (if applicable): home-assistant/home-assistant.io#<home-assistant.io PR number goes here>

Example entry for configuration.yaml (if applicable):

Checklist:

  • The code change is tested and works locally.
  • Local tests pass with tox. Your PR cannot be merged unless tests pass
  • There is no commented out code in this PR.

If user exposed functionality or configuration variables are added/changed:

If the code communicates with devices, web services, or third-party tools:

  • New dependencies have been added to the REQUIREMENTS variable (example).
  • New dependencies are only imported inside functions that use them (example).
  • New or updated dependencies have been added to requirements_all.txt by running script/gen_requirements_all.py.
  • New files were added to .coveragerc.

If the code does not interact with devices:

  • Tests have been added to verify that the new code works.
@fabaff

This comment has been minimized.

Copy link
Member

fabaff commented Dec 29, 2018

Isn't defusedxml as drop-in replacement? If so, I think that we are fine.

@scop

This comment has been minimized.

Copy link
Contributor

scop commented Dec 29, 2018

Yep, for ElementTree it just installs a few handlers that disable entity declarations and external entity fetches; the actual parser is still the same ElementTree. https://github.com/tiran/defusedxml/blob/master/defusedxml/ElementTree.py

@fabaff

fabaff approved these changes Dec 29, 2018

@fabaff fabaff merged commit f925d9c into home-assistant:dev Dec 29, 2018

5 checks passed

Hound No violations found. Woof!
WIP ready for review
Details
cla-bot Everyone involved has signed the CLA
continuous-integration/travis-ci/pr The Travis CI build passed
Details
coverage/coveralls Coverage decreased (-0.008%) to 93.063%
Details

@wafflebot wafflebot bot removed the in progress label Dec 29, 2018

mxworm added a commit to mxworm/home-assistant that referenced this pull request Dec 30, 2018

Merge branch 'dev' into current
* dev: (44 commits)
  Fix ADS light when parameter adsvar_brightness is not set (home-assistant#19636)
  Bump pyHik library to 0.1.9 to improve device support. (home-assistant#19656)
  Use aioharmony for remote.harmony platform (home-assistant#19595)
  Add RaspyRFM switch platform (home-assistant#19130)
  Only bind clusters in ZHA remote entity (home-assistant#19577)
  Use async_configure for ZHA IAS binary sensor (home-assistant#19629)
  Improve Wemo setup speed (home-assistant#19563)
  Support knx operation types (home-assistant#19546)
  Use xml.etree through defusedxml (home-assistant#19640)
  Fix cpu_temp issue on Vero 4K (home-assistant#19638)
  Added events STARTED, RESTARTED AND PAUSED (home-assistant#19516)
  Revert "Bump pyotgw to 0.4b0 (home-assistant#19618)" (home-assistant#19635)
  Upgrade to async_upnp_client==0.13.8 (home-assistant#19634)
  Upgraded pyarlo to 0.2.3 (home-assistant#19626)
  Fix cpu_temp issue on Odroid (home-assistant#19620)
  Bump pyotgw to 0.4b0 (home-assistant#19618)
  Add additional neato alerts and errors (home-assistant#19608)
  LCN component and light platform (home-assistant#18621)
  Systemmonitor - add device_class property (home-assistant#19614)
  Upgrade huawei-lte-api to 1.1.1 (home-assistant#19615)
  ...

@scop scop deleted the scop:defusedxml branch Dec 30, 2018

@balloob balloob referenced this pull request Jan 10, 2019

Merged

0.85.0 #19897

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment