Policies for tarfile.extractall, a.k.a. fixing CVE-2007-4559

Thank you! That was fast :‍)

The 3.12 implementation is merged. I’ll start on the 3.11 backport, and update the PEP after its docs are rebuilt, so I can link them in the canonical-doc admonition.

3 Likes