Skip to content

fix: ensure network and load_dtd are disabled in xml reading - #167

Merged
stevenhsd merged 1 commit into
release_v010from
fix/gr-improve_security_on_xml_reader
Sep 29, 2026
Merged

stevenhsd merged 1 commit into
release_v010from
fix/gr-improve_security_on_xml_reader

Conversation

@georgeRobertson

Copy link
Copy Markdown
Contributor

TLDR of changes

Improve reading security of lxml XML readers.

  • Set no_network is set to False to prevent network access against remote resources. Docs indicate this should already be set but couldn't fully confirm - so just set for 100% assurance.
  • Also set load_dtd to False to disable dtd functionality as not used and can be dangerous to leave on. This was less clear in the docs as to whether it was on or off. This makes sure it's off.

What kind of changes does this PR introduce?

Tick all that apply

  • fix: A bug fix. Correlates with PATCH in SemVer
  • feat: A new feature. Correlates with MINOR in SemVer
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semi-colons, etc)
  • refactor: A code change that neither fixes a bug nor adds a feature
  • perf: A code change that improves performance
  • test: Adding missing or correcting existing tests
  • build: Changes that affect the build system or external dependencies (example scopes: pip, docker, npm)
  • ci: Changes to CI configuration files and scripts (example scopes: GitLabCI)

Please check if the PR fulfills these requirements

  • I have read and followed the Contributing guidance
  • Docs have been added / updated
  • Tests and Linting in the CI are passing
  • Changes have been reviewed and approved by a Project Maintainer

@sonarqubecloud

Copy link
Copy Markdown

@stevenhsd
stevenhsd merged commit b3e03b4 into release_v010 Sep 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants