mirror of https://github.com/python/cpython
gh-57684: Document safe path in What's New in Python 3.11 (#92362)
Mention also -P and PYTHONSAFEPATH in the Security Considerations page.
This commit is contained in:
parent
329afe78c3
commit
5f29268283
|
@ -32,3 +32,9 @@ The following modules have specific security considerations:
|
||||||
* :mod:`xml`: :ref:`XML vulnerabilities <xml-vulnerabilities>`
|
* :mod:`xml`: :ref:`XML vulnerabilities <xml-vulnerabilities>`
|
||||||
* :mod:`zipfile`: :ref:`maliciously prepared .zip files can cause disk volume
|
* :mod:`zipfile`: :ref:`maliciously prepared .zip files can cause disk volume
|
||||||
exhaustion <zipfile-resources-limitations>`
|
exhaustion <zipfile-resources-limitations>`
|
||||||
|
|
||||||
|
The :option:`-I` command line option can be used to run Python in isolated
|
||||||
|
mode. When it cannot be used, the :option:`-P` option or the
|
||||||
|
:envvar:`PYTHONSAFEPATH` environment variable can be used to not prepend a
|
||||||
|
potentially unsafe path to :data:`sys.path` such as the current directory, the
|
||||||
|
script's directory or an empty string.
|
||||||
|
|
|
@ -79,6 +79,12 @@ New typing features:
|
||||||
* :pep:`673`: ``Self`` type.
|
* :pep:`673`: ``Self`` type.
|
||||||
* :pep:`675`: Arbitrary literal string type.
|
* :pep:`675`: Arbitrary literal string type.
|
||||||
|
|
||||||
|
Security improvements:
|
||||||
|
|
||||||
|
* New :option:`-P` command line option and :envvar:`PYTHONSAFEPATH` environment
|
||||||
|
variable to not prepend a potentially unsafe path to :data:`sys.path` such as
|
||||||
|
the current directory, the script's directory or an empty string.
|
||||||
|
|
||||||
|
|
||||||
New Features
|
New Features
|
||||||
============
|
============
|
||||||
|
|
Loading…
Reference in New Issue