Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commit 022476a

Browse files
Update README.rst
1 parent 1ff3901 commit 022476a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

‎README.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ With that said, **I am happy to review pull requests and give you write permissi
2828

2929
There were a lot of great contributors to this project, I plan on working on other projects like `detect-secrets`_ and others (e.g. Pyre eventually) in the future if you'd like to work together more :)
3030

31-
If you are a security engineer with e.g. a Python codebase without type annotations, that Pyre won't handle, I would suggest you replace your sinks with a secure wrapper (something like `defusedxml`_), and alert off any uses of the standard sink. You can use `Bandit`_ to do this but you will have to trim it a lot, due to the high false-positive rate.
31+
If you are a security engineer with e.g. a Python codebase without type annotations, that Pyre won't handle, I would suggest you replace your sinks with a secure wrapper (something like `defusedxml`_), and alert off any uses of the standard sink. You can use `Bandit`_ to do this since dataflow analysis is not required, but you will have to trim it a lot, due to the high false-positive rate.
3232

3333
.. _Pyre: https://github.com/facebook/pyre-check
3434
.. _README's in most directories: https://github.com/python-security/pyt/tree/master/pyt#how-it-works

0 commit comments

Comments
(0)

AltStyle によって変換されたページ (->オリジナル) /