Bug#933921: src:python-tablib: Unsafe use of yaml.load()

2019-08-06 Thread Thomas Goirand
On 8/6/19 1:58 AM, Joseph Herlant wrote: > Hi, > > Thanks Scott for the report. > Tomas: the repository in Openstack was archived long ago because it > was ported to https://salsa.debian.org/python-team/modules/python-tablib > The module is used by other packages than openstack (like > django-tabl

Bug#933921: src:python-tablib: Unsafe use of yaml.load()

2019-08-05 Thread Joseph Herlant
Hi, Thanks Scott for the report. Tomas: the repository in Openstack was archived long ago because it was ported to https://salsa.debian.org/python-team/modules/python-tablib The module is used by other packages than openstack (like django-tables if I remember correctly), so could you please hold o

Bug#933921: src:python-tablib: Unsafe use of yaml.load()

2019-08-05 Thread Thomas Goirand
On 8/5/19 7:35 AM, Scott Kitterman wrote: > Package: src:python-tablib > Version: 0.12.1-2 > Severity: grave > Tags: security > Justification: user security hole > > The new version of pyyaml no longer allows use of yaml.load() without a > loader being specifed. This raises a deprecation warning

Bug#933921: src:python-tablib: Unsafe use of yaml.load()

2019-08-04 Thread Scott Kitterman
Package: src:python-tablib Version: 0.12.1-2 Severity: grave Tags: security Justification: user security hole The new version of pyyaml no longer allows use of yaml.load() without a loader being specifed. This raises a deprecation warning which has caused and autopkgtest failure on this package.