Security
Posting 2.11.1 fixes a code-execution vulnerability. Upgrading is recommended for everyone.
Older versions loaded request files (.posting.yaml) with a YAML loader that constructs Python objects. A crafted request file could run arbitrary commands as soon as Posting loaded the collection containing it, for example after cloning a repository or opening a shared collection.
- Request files are now loaded with YAML's safe loader, and Python object tags are rejected (reported in #348 and #383).
- Theme files are now loaded with the safe loader too.
Request files that Posting saved itself are unaffected and load as before.
Upgrade: uv tool upgrade posting, or pipx upgrade posting