Skip to content

Commit e699d8b

Browse files
committed
docs: Add Security comment (SSRF)
1 parent b95ba7a commit e699d8b

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

ocdskit/combine.py

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -195,6 +195,7 @@ def merge(
195195
tag = get_ocds_patch_tag(packager.version)
196196
if packager.package['extensions']:
197197
# `extensions` is an insertion-ordered dict at this point.
198+
# Security: Potential SSRF via extension URLs.
198199
builder = ProfileBuilder(tag, list(packager.package['extensions']))
199200
schema = builder.patched_release_schema()
200201
else:

0 commit comments

Comments
 (0)