Skip to content

Conversation

@jscheffl
Copy link
Contributor

Wake-up call after reading https://daniel.haxx.se/blog/2025/05/16/detecting-malicious-unicode/


^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@jscheffl jscheffl added backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch backport-to-v2-11-test Mark PR with this label to backport to v2-11-test branch labels May 25, 2025
files: ^\.github/workflows/.*$|^\.github/actions/.*$
require_serial: true
entry: zizmor
- repo: https://github.com/lirantal/anti-trojan-source
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like no activity on this repo since last 3 years. not sure are they are maintaining it or not.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point. Was just picking the first I could find.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As further discussed in https://apache-airflow.slack.com/archives/C015SLQF059/p1748180085592359 --- maybe we rather roll-our own as the list to cover is way larger than the pre-commit I proposed here.

@jscheffl
Copy link
Contributor Author

At least ' char FF07 FULLWIDTH APOSTROPHE was not taken seroious by the pre-commit.

@jscheffl jscheffl requested a review from vincbeck as a code owner May 25, 2025 17:26
@jscheffl
Copy link
Contributor Author

Closing as not needed.

@jscheffl jscheffl closed this May 25, 2025
@jscheffl jscheffl deleted the feature/add-detection-for-malicious-unicode branch October 5, 2025 07:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:dev-tools backport-to-v2-11-test Mark PR with this label to backport to v2-11-test branch backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants