Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add deserialization warning for Oj.load/object_load #1334

merged 1 commit into from Mar 27, 2019


None yet
1 participant
Copy link

commented Mar 18, 2019

As pointed out here, Oj.load by default will deserialize arbitrary Ruby objects from JSON.

This updates the deserialization check to look for:

  • Oj.load with default options
  • Oj.object_load with any options

@presidentbeef presidentbeef changed the title Add deserialization warning for Oj.load/load_object Add deserialization warning for Oj.load/object_load Mar 18, 2019

@presidentbeef presidentbeef merged commit 86ac2fa into master Mar 27, 2019

4 of 5 checks passed

codeclimate 1 issue to fix
ci/circleci Your tests passed on CircleCI!
codeclimate/diff-coverage 100% (90% threshold)
codeclimate/total-coverage 94% (0.0% change)
continuous-integration/travis-ci/pr The Travis CI build passed

@presidentbeef presidentbeef deleted the oj_deserialize branch Mar 27, 2019

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.