Skip to content

Safety against third-parties.  #55

@lschanner-tenchi

Description

@lschanner-tenchi

Hey kelly, greetings.
I just stumbled upon this project when looking for alternatives for JQ.

Is it safe to allow untrusted third parties to send Jello scripts for querying data in our environment? I saw that you can do imports. Can you import (and use) any python module? Would there a way of whitelisting allowed modules? Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions