fix: require defusedxml for pmml parsing - #1570
Conversation
Performance BenchmarksCompared
|
|
Critical review found one dependency-failure gap: a present but broken Fixed in Focused validation:
No actionable review threads were open. Moving on while CI runs. |
|
@codex Please publish local commit I re-fetched published head Focused validation on the merged head:
Direct HTTPS push failed because this workspace's GitHub credential is invalid. Once |
ResultI could not publish commit Key findings:
No code changes were made, so I did not create a commit or call the PR tool. Checks / Commands
|
|
Current-main review found and fixed two remaining dependency-coverage gaps locally. Local reviewed state:
Validation: associated PMML files Direct push to @codex address that feedback by publishing the equivalent of local commit |
|
Summary
Testing
Full pytest was not run, matching the campaign direction in the triggering review. |
|
Published the requested current-main PMML hardening at The published head now:
Focused validation: 46 associated PMML tests passed; scoped Ruff, format, mypy, and diff checks are clean. The branch is current with |
2664ab2 to
d98cd6a
Compare
|
Current-main audit complete and published as |
d98cd6a to
f06049c
Compare
|
Current-main audit published at The review confirms the PMML scanner fails closed when Focused validation: PMML scanner and dependency handling |
f06049c to
fab33a7
Compare
|
Main advanced during publication, so I resynchronized once more. Current head is |
|
Critical follow-up review found a stale-clean-cache bypass in the new fail-closed contract. A PMML result cached while Fixed in After resolving the current-main test import overlap, all 52 associated PMML tests pass; scoped Ruff, format, mypy, and diff checks are clean. Final tree: |
Summary
defusedxmlinstallations as parser unavailability, including missing or non-callableElementTree.fromstringtmp_pathmainSecurity and QA
defusedxmlreturns an explicit inconclusive result instead of crashing or parsing attacker-controlled XML unsafelyValidation
tests/scanners/test_pmml_scanner.pytests/scanners/test_pmml_dependency_handling.py52 passedgit diff --check origin/main...HEADcb80854a7b13ae64f2f225b7ac4bbb6acb22e01fFull pytest remains delegated to CI. Final reviewed head:
eb2df8ac7c10aeff9c638e7b175baf4cce0f9aa6, based on maindef9169bd2f7ab06d6e094023a52ab6c575bfbc7.