[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#862373: The State of the YAML



On Fri, 18 May 2018 11:09:23 +0200, gregor herrmann wrote:

> Quick status update on the perl YAML modules and the problem of
> instantiating objects:
> 
> * libyaml-syck-perl has $YAML::LoadBlessed since a long time
> * libyaml-libyaml-perl since 0.69 and libyaml-perl since 1.25 have
>   added $YAML::LoadBlessed as well
> * all three by default set it to 1 
> 
> (and YAML::Tiny is not affected as far as I know)

(Neither the new YAML::PP)
 
Good news: YAML, YAML::XS, and YAML::Syck changed their default for
the ::LoadBlessed variable to false on Monday, and I just uploaded
the three packages to unstable, closing the respective RC bugs.

Further information:
http://blogs.perl.org/users/tinita/2020/01/making-yamlpm-yamlsyck-and-yamlxs-safer-by-default.html

Credits go to Tina, Todd, and Ingy for this coordinated effort!


Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-   NP: Donovan: Season of The Witch

Attachment: signature.asc
Description: Digital Signature


Reply to: