[PR #4031] improve: extract method for safe loading yaml file and avoid using PyYaml's FullLoader #24375

Closed
opened 2026-02-21 20:22:53 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/4031

State: closed
Merged: Yes


Description

  • extract a general method for loading YAML file into object, in following step
    • check the file path existence and properly open / close the IO stream in place
    • use yaml's safe_load method
  • enable ruff's S506 rule (https://docs.astral.sh/ruff/rules/unsafe-yaml-load/) to avoid possible unsafe yaml loading
  • benefits:

Type of Change

Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update, included: Dify Document
  • Improvement, including but not limited to code refactoring, performance optimization, and UI/UX improvement
  • Dependency upgrade

How Has This Been Tested?

  • add unit tests

Suggested Checklist:

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • My changes generate no new warnings
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
  • optional I have made corresponding changes to the documentation
  • optional I have added tests that prove my fix is effective or that my feature works
  • optional New and existing unit tests pass locally with my changes
**Original Pull Request:** https://github.com/langgenius/dify/pull/4031 **State:** closed **Merged:** Yes --- # Description - extract a general method for loading YAML file into object, in following step - check the file path existence and properly open / close the IO stream in place - use `yaml`'s `safe_load` method - enable ruff's S506 rule (https://docs.astral.sh/ruff/rules/unsafe-yaml-load/) to avoid possible unsafe yaml loading - benefits: - avoid using `yaml.load` directly , according to Yaml's docs for deprecation: https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation - skip repeated opening file stream or checking file existence - prevent hanging code indent for opening file - unified method for handling errors - properly covered by unit tests ## Type of Change Please delete options that are not relevant. - [ ] Bug fix (non-breaking change which fixes an issue) - [ ] New feature (non-breaking change which adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to not work as expected) - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] Improvement, including but not limited to code refactoring, performance optimization, and UI/UX improvement - [ ] Dependency upgrade # How Has This Been Tested? - [x] add unit tests # Suggested Checklist: - [x] I have performed a self-review of my own code - [x] I have commented my code, particularly in hard-to-understand areas - [x] My changes generate no new warnings - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods - [ ] `optional` I have made corresponding changes to the documentation - [ ] `optional` I have added tests that prove my fix is effective or that my feature works - [ ] `optional` New and existing unit tests pass locally with my changes
yindo added the pull-request label 2026-02-21 20:22:53 -05:00
yindo closed this issue 2026-02-21 20:22:53 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#24375