pierrejeambrun commented on code in PR #32303:
URL: https://github.com/apache/airflow/pull/32303#discussion_r1249498015


##########
airflow/cli/commands/provider_command.py:
##########
@@ -17,7 +17,7 @@
 """Providers sub-commands."""
 from __future__ import annotations
 
-import re
+import re2 as re

Review Comment:
   re is vulnerable to attacks. re2 does not allow exponential backtracking.
   
   You can find more info here:
   https://lists.apache.org/thread/lytmbn1xf9vwgwfwgp4vrm3vshn8p1tm
   https://github.com/airflow-s/airflow-s/issues/19



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to