Sep-09-2019, 12:32 PM
(Sep-09-2019, 01:44 AM)Larz60+ Wrote: It's not unsafe, it's just that the author depreciated using yaml.load without specific loader=whatever clause apparently there was using just yaml.load is capable of being exploited, not so if loader= clause provided.
Thanks very much for your reply. It makes sense! However, I just don't understand why that same yaml.load(f) command appears right below the warning? Do you know the reason for this? I am still learning
