-=| gregor herrmann, 18.05.2018 11:09:23 +0200 |=- > Quick status update on the perl YAML modules and the problem of > instantiating objects: > > * libyaml-syck-perl has $YAML::LoadBlessed since a long time > * libyaml-libyaml-perl since 0.69 and libyaml-perl since 1.25 have > added $YAML::LoadBlessed as well > * all three by default set it to 1 > > (and YAML::Tiny is not affected as far as I know) > > So I guess we have to consider if we're happy with the ability to > turn off loading objects and recommend it to consumers and close the > bugs; or if we want to change the defaults, which means setting > $YAML::LoadBlessed to 0 in all three packages.
FWIW I'd go with the second option, with a note in debian/NEWS. For me the cost of the possible breakage (easily fixed) is less than the gain of protecting everyone else. (I don't use the object instantiation functionality) -- dam