jello icon indicating copy to clipboard operation
jello copied to clipboard

Safety against third-parties.

Open lschanner-tenchi opened this issue 1 year ago • 3 comments

Hey kelly, greetings. I just stumbled upon this project when looking for alternatives for JQ.

Is it safe to allow untrusted third parties to send Jello scripts for querying data in our environment? I saw that you can do imports. Can you import (and use) any python module? Would there a way of whitelisting allowed modules? Thanks!

lschanner-tenchi avatar Jan 19 '23 11:01 lschanner-tenchi