triage icon indicating copy to clipboard operation
triage copied to clipboard

Consider moving back to yaml.full_load for matrix metadata

Open shaycrk opened this issue 3 years ago • 0 comments

See discussion associated with #835

We switched to yaml.load when upgrading pyYAML to 5.4; moving back to full_load would provide some security enhancements but require changing how we represent as_of_time and feature lists in a way that would break compatibility with matrices generated by previous versions of triage, so we should decide if the improvements outweigh that cost.

shaycrk avatar Mar 30 '21 17:03 shaycrk