| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
I think it's unlikely that this will be used in an exploit, but we treat `for char in string: ...` as preserving taint, so we might as well do the same for this iterator.
There was a problem hiding this comment.
The narrow model follows existing taint semantics and has focused regression coverage, with no unresolved findings.
Review effort: Balanced
Findings: None
Adds taint-flow modeling for Python 3.15’s unicodedata.iter_graphemes, consistent with existing string-iteration behavior.
Changes:
| File | Description |
|---|---|
| python/ql/test/library-tests/frameworks/stdlib/test_unicodedata.py | Tests taint propagation and negative cases. |
| python/ql/lib/semmle/python/frameworks/Stdlib.model.yml | Adds the iter_graphemes taint summary. |
| python/ql/lib/change-notes/2026-09-30-python315-graphemes.md | Records the new modeling support. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
I think it's unlikely that this will be used in an exploit, but we treat for char in string: ... as preserving taint, so we might as well do the same for this iterator.