[Csv] Patch to remove eval from csv sniffer

Andrew McNamara andrewm at object-craft.com.au
Thu Jun 12 04:05:03 CEST 2003

The patch by Raymond Hettinger mentioned here:


makes a lot of sense. The question is - should it be applied now? We're
in the 55th minute of the 11th hour for 2.3, and changes are generally
unwelcome. This change changes the sniffer's behaviour slightly, but
it's probably better to do this now, than after 2.3 is released (and
it's a potential security problem).

Andrew McNamara, Senior Developer, Object Craft

More information about the Csv mailing list