Skip to content

lxml should be removed from use-defused-xml #1086

@xmo-odoo

Description

@xmo-odoo

Describe the bug
defusedxml.lxml was only ever an example and is deprecated.

Ideally there should instead be a rule checking that entity resolution is disabled, and possibly other lxml-related issues though the latter may alresady exist.

To Reproduce
Run semgrep on a codebase with lxml, it tells you to remove lxml.

Expected behavior
It shouldn't do that.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions