Skip to content

Remove lxml from DUO107 - #44

Open
hughdavenport wants to merge 1 commit into
dlint-py:masterfrom
hughdavenport:DUO107-fixes
Open

Remove lxml from DUO107#44
hughdavenport wants to merge 1 commit into
dlint-py:masterfrom
hughdavenport:DUO107-fixes

Conversation

@hughdavenport

Copy link
Copy Markdown

hughdavenport added a commit to hughdavenport/semgrep-rules that referenced this pull request May 18, 2022
As mentioned in semgrep#1086, defusedxml.lxml was only ever an example and is deprecated. I've created a PR on the dlint project at dlint-py/dlint#44.
@mschwager

Copy link
Copy Markdown
Contributor

Hi there,

Good catch, thanks for bringing this to my attention. I agree with the spirit of this task, however I think it makes sense to wait until tiran/defusedxml#38 is fixed (i.e. defusedxml.lxml is removed) and a new version of defusedxml is released until we remove the linter.

minusworld pushed a commit to semgrep/semgrep-rules that referenced this pull request May 20, 2022
As mentioned in #1086, defusedxml.lxml was only ever an example and is deprecated. I've created a PR on the dlint project at dlint-py/dlint#44.
@gforcada

Copy link
Copy Markdown

Maybe it is time to finally remove DUO107 now? It's been more than 4/5 years... at least maybe make it disabled by default ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants