Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bleach is deprecated suggestion for using nh3 instead #1051

Closed
Soham7777777 opened this issue Dec 31, 2024 · 3 comments
Closed

Bleach is deprecated suggestion for using nh3 instead #1051

Soham7777777 opened this issue Dec 31, 2024 · 3 comments

Comments

@Soham7777777
Copy link

On 2023-01-23, the Bleach package used for sanitizing HTML was deprecated. The nh3 package is best alternative in my opinion. flask-security still uses bleach with its "common" set of packages. Please change this as soon as possible, otherwise this is counted as security issue.

@jwag956
Copy link
Collaborator

jwag956 commented Dec 31, 2024

Thanks for the issue - nh3 looks interesting. While bleach is 'deprecated' it is still being supported. Are you aware of any security reports against it?

@ThiefMaster
Copy link

Please change this as soon as possible, otherwise this is counted as security issue.

No it isn't. Read the relevant part of the issue you have even linked to:

We will continue to support Bleach:

  • security updates
  • support for new Python versions
  • fixes for egregious bugs

@Soham7777777
Copy link
Author

Soham7777777 commented Jan 1, 2025

Alright, My bad. Its ok to use bleach. Not a security issue.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 28, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

3 participants