Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add tree-sitter to the list of allowed external packages #138

Merged
merged 2 commits into from
Jun 11, 2024

Conversation

sobolevn
Copy link
Contributor

@sobolevn sobolevn commented Jun 8, 2024

@srittau srittau merged commit 734c5ff into typeshed-internal:main Jun 11, 2024
3 checks passed
@Akuli
Copy link

Akuli commented Jun 11, 2024

I don't like how we need to add relatively obscure packages to a global allowlist, but I'm not sure if there is a better solution. I guess we just need to carefully avoid step 6 of #61 (comment).

That said, it would be nice to document the security aspects of stub_uploader somewhere, maybe to a markdown file in this repo, instead of referring to old PR comments whenever security comes up. I might give it a try within the next few weeks.

Security is IMO the most important thing for stub_uploader to get right, because a malicious types_requests could very quickly gain access to many dev machines, and from there to many production servers and such.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants