• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

RH-FMK / skt / 1257
66%

Build:
DEFAULT BRANCH: master
Ran 05 Sep 2018 07:59AM UTC
Jobs 1
Files 10
Run time 1s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
1257

push

travis-ci

spbnick
Use defusedxml for XML parsing

In theory, a user can pass a maliciously crafted XML, exploiting the
server/testing side. While currently it means they would exploit their
own infrastructure, if in the future there is a publicly available
service allowing people to run eg. custom tests or pass their own
Beaker XMLs, the possibility to expoit the organization running the
service grows exponentially.

xml.ElementTree is safe against external entity expansion, DTD retrieval
and decompression bomb, but not against exponential entity expansion or
quadratic blowup entity expansion. defusedxml provides a modified
fromstring method for parsing untrusted XMLs, to prevent the exploits
original ElementTree is not protected against.

Signed-off-by: Veronika Kabatova <vkabatov@redhat.com>

309 of 525 branches covered (58.86%)

Branch coverage included in aggregate %.

997 of 1438 relevant lines covered (69.33%)

0.69 hits per line

Jobs
ID Job ID Ran Files Coverage
1 1257.1 (TOX_ENV=py27,flake8,pylint) 05 Sep 2018 07:59AM UTC 0
66.53
Travis Job 1257.1
Source Files on build 1257
Detailed source file information is not available for this build.
  • Back to Repo
  • Travis Build #1257
  • 64cac508 on github
  • Prev Build on master (#1252)
  • Next Build on master (#1260)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc