-
Notifications
You must be signed in to change notification settings - Fork 915
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
(security) Path Traversal #3474
Comments
SummaryIn discussion with @noklam and @merelcht - The only way to silence the Snyk warning is to check the path provided by the env variable The decision then is to make no changes to address this but rely on the user to make sure that the path to the logging file is not arbitrary. |
To supplement this. it's fair to say that it's the user's responsibility to make sure they use a trusted file for the logging. If the Kedro pipeline is exposed via API or embedded in application. We recommend not to expose |
Description
Flagged by Snyk as Medium priority
Context
https://github.com/kedro-org/kedro/blob/main/kedro/framework/project/__init__.py#L218-L220
Possible Implementation
The text was updated successfully, but these errors were encountered: