Repository navigation
Implement zipfile.Path.is_symlink #119588
Copy link
Copy link
Closed
Description
Activity
- added a commit that references this issue
on May 27, 2024 The
is_symlinkwas added in Python 3.12 (#102018) (note the backports of that PR only included one bugfix), so this change can be backported to Python 3.12 as a bugfix (no need to flag as a security fix).- added a commit that references this issue
on May 27, 2024 - added a commit that references this issue
on Jun 4, 2024 Triage: closing because the PR has been merged, please re-open if still needed. Thanks!
Metadata
Metadata
Assignees
Labels
No labels
Projects
- StatusShow more project fieldsDone
In jaraco/zipp#117, I learned that the current implementation of
is_symlinkmight have a security risk if a user is relying on it to ensure that a zipfile has no symlinks before using another tool to extract it.zipp 3.19.0 adds an implementation for
Path.is_symlinkto alleviate this risk.CPython should adopt this change as well, possibly as a security fix.
Linked PRs