github darrenburns/posting 2.11.1
2.11.1 - Security fix for request YAML loading

latest release: 2.11.2
9 hours ago

Security

Posting 2.11.1 fixes a code-execution vulnerability. Upgrading is recommended for everyone.

Older versions loaded request files (.posting.yaml) with a YAML loader that constructs Python objects. A crafted request file could run arbitrary commands as soon as Posting loaded the collection containing it, for example after cloning a repository or opening a shared collection.

  • Request files are now loaded with YAML's safe loader, and Python object tags are rejected (reported in #348 and #383).
  • Theme files are now loaded with the safe loader too.

Request files that Posting saved itself are unaffected and load as before.

Upgrade: uv tool upgrade posting, or pipx upgrade posting

Don't miss a new posting release

NewReleases is sending notifications on new releases.