Removed shell=True from subprocess commands that require user inputs#7875
Merged
glenn-jocher merged 6 commits intoultralytics:masterfrom May 19, 2022
Merged
Removed shell=True from subprocess commands that require user inputs#7875glenn-jocher merged 6 commits intoultralytics:masterfrom
glenn-jocher merged 6 commits intoultralytics:masterfrom
Conversation
… Also removed unused arguments
for more information, see https://pre-commit.ci
Contributor
There was a problem hiding this comment.
👋 Hello @JWLee89, thank you for submitting a YOLOv5 🚀 PR! To allow your work to be integrated as seamlessly as possible, we advise you to:
- ✅ Verify your PR is up-to-date with upstream/master. If your PR is behind upstream/master an automatic GitHub Actions merge may be attempted by writing /rebase in a new comment, or by running the following code, replacing 'feature' with the name of your local branch:
git remote add upstream https://github.com/ultralytics/yolov5.git
git fetch upstream
# git checkout feature # <--- replace 'feature' with local branch name
git merge upstream/master
git push -u origin -f- ✅ Verify all Continuous Integration (CI) checks are passing.
- ✅ Reduce changes to the absolute minimum required for your bug fix or feature addition. "It is not daily increase but daily decrease, hack away the unessential. The closer to the source, the less wastage there is." -Bruce Lee
Member
|
@JWLee89 PR is merged. Thank you for your contributions to YOLOv5 🚀 and Vision AI ⭐ |
Contributor
Author
|
@glenn-jocher Thank you for reviewing my PR. Looking forward to working on yolov5 during my downtime! |
tdhooghe
pushed a commit
to tdhooghe/yolov5
that referenced
this pull request
Jun 10, 2022
…ltralytics#7875) * Removed shell=True from subprocess commands that require user inputs. Also removed unused arguments * [pre-commit.ci] auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci * Added check=True * Revert line add Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com> Co-authored-by: Glenn Jocher <glenn.jocher@ultralytics.com>
ctjanuhowski
pushed a commit
to ctjanuhowski/yolov5
that referenced
this pull request
Sep 8, 2022
…ltralytics#7875) * Removed shell=True from subprocess commands that require user inputs. Also removed unused arguments * [pre-commit.ci] auto fixes from pre-commit.com hooks for more information, see https://pre-commit.ci * Added check=True * Revert line add Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com> Co-authored-by: Glenn Jocher <glenn.jocher@ultralytics.com>
Member
|
@JWLee89 you're welcome! Our team is grateful for your valuable contributions to YOLOv5. Let us know if you have any questions or need assistance during your work on the project. Happy coding! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR involves the following changes
shell=Truefrom subprocess calls where user-defined inputs are provided (to prevent possible unwanted injection)I ran the scripts after modification inside of the yolo docker container and checked manually to see if it works.
If needed I can also post serialized outputs and computational graph generated by netron.
🛠️ PR Summary
Made with ❤️ by Ultralytics Actions
🌟 Summary
Enhancements to model export functionality in 'ultralytics/yolov5.'
📊 Key Changes
modelandimparameters from OpenVINO, TensorFlow GraphDef (pb), Edge TPU, and TensorFlow.js export functions.subprocess.check_outputandsubprocess.runwithshell=Trueto use.split()method, enhancing security and preventing shell injection vulnerabilities.🎯 Purpose & Impact
shell=Trueprevents execution of arbitrary code, making exports more secure.