Skip to content

Commit

Permalink
fix(iast): add psycopg and psycopg2 to denylist (#11571)
Browse files Browse the repository at this point in the history
Code security: This fix resolves an issue where the patching of psycopg
is producing bad code. Since it's not required to patch psycopg or
psycopg2 modules, we will avoid patching them altogether, with the
benefit of a small performance improvement.

## Checklist
- [x] PR author has checked that all the criteria below are met
- The PR description includes an overview of the change
- The PR description articulates the motivation for the change
- The change includes tests OR the PR description describes a testing
strategy
- The PR description notes risks associated with the change, if any
- Newly-added code is easy to change
- The change follows the [library release note
guidelines](https://ddtrace.readthedocs.io/en/stable/releasenotes.html)
- The change includes or references documentation updates if necessary
- Backport labels are set (if
[applicable](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting))

## Reviewer Checklist
- [x] Reviewer has checked that all the criteria below are met 
- Title is accurate
- All changes are related to the pull request's stated goal
- Avoids breaking
[API](https://ddtrace.readthedocs.io/en/stable/versioning.html#interfaces)
changes
- Testing strategy adequately addresses listed risks
- Newly-added code is easy to change
- Release note makes sense to a user of the library
- If necessary, author has acknowledged and discussed the performance
implications of this PR as reported in the benchmarks PR comment
- Backport labels are set in a manner that is consistent with the
[release branch maintenance
policy](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting)

---------

Co-authored-by: Alberto Vara <[email protected]>
  • Loading branch information
gnufede and avara1986 authored Nov 29, 2024
1 parent 2a58b90 commit b6ff124
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 0 deletions.
3 changes: 3 additions & 0 deletions ddtrace/appsec/_iast/_ast/ast_patching.py
Original file line number Diff line number Diff line change
Expand Up @@ -280,6 +280,9 @@
"pkg_resources.",
"pluggy.",
"protobuf.",
"psycopg.", # PostgreSQL adapter for Python (v3)
"_psycopg.", # PostgreSQL adapter for Python (v3)
"psycopg2.", # PostgreSQL adapter for Python (v2)
"pycparser.", # this package is called when a module is imported, propagation is not needed
"pytest.", # Testing framework
"_pytest.",
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
fixes:
- |
Code security: This fix resolves a patching issue with `psycopg3`.

0 comments on commit b6ff124

Please sign in to comment.