Skip to content

harden: use yaml.safe_load in base_config.py - #13661

Open
dajiaohuang wants to merge 1 commit into
tensorflow:masterfrom
dajiaohuang:fix/yaml-safe-load-base-config
Open

dajiaohuang wants to merge 1 commit into
tensorflow:masterfrom
dajiaohuang:fix/yaml-safe-load-base-config

Conversation

@dajiaohuang

Copy link
Copy Markdown

Description

Use yaml.safe_load instead of yaml.load with FullLoader in base_config.py for security hardening (gitlab.bandit.B506).

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • Security fix

Tests

Basic verification was performed. The change replaces yaml.load(f, Loader=yaml.FullLoader) with yaml.safe_load(f), which is the recommended remediation for bandit B506.

Checklist

  • I have signed the Contributor License Agreement (CLA).
  • My code follows the coding guidelines of this project.
  • I have performed a self-review of my own code.
  • My changes generate no new warnings.

Fixes #13652

@google-cla

google-cla Bot commented Sep 25, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant