uranusjr commented on issue #24740:
URL: https://github.com/apache/airflow/issues/24740#issuecomment-1170758230

   If you think GitSync is insecure, I’d say allowing uploading file via the 
REST API is even more so. A DAG file is run as plain Python code in the 
interpreter, and it’s against code injection prevention 101 to expose it via 
any web API.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to