Replace urllib with requests to Restrict Unsafe Protocol Handling#14227
Open
Tanmaykaturi wants to merge 2 commits intoTheAlgorithms:masterfrom
Open
Replace urllib with requests to Restrict Unsafe Protocol Handling#14227Tanmaykaturi wants to merge 2 commits intoTheAlgorithms:masterfrom
Tanmaykaturi wants to merge 2 commits intoTheAlgorithms:masterfrom
Conversation
…e-detected-458-KAphqxWbd0 fix: semgrep-dynamic-urllib-use-detected
mindaugl
approved these changes
Jan 30, 2026
mindaugl
reviewed
Jan 31, 2026
Contributor
mindaugl
left a comment
There was a problem hiding this comment.
There are some ruff issues outstanding.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Describe your change:
Checklist:
This PR replaces the use of urllib.request.urlopen() with requests.get() for fetching the dataset URL.While the current URL is hardcoded and safe, urllib supports additional protocols such as file:// and ftp://. If the URL ever becomes dynamic or user-controlled in the future, this could introduce a risk of unintended local file access or data exposure.The requests library only allows http:// and https:// by default, which helps prevent entire classes ofprotocol-based vulnerabilities. This change improves security posture through defense-in-depth while preserving identical functionality for valid web requests.