See how travis shirk compares to other vendors in security performance
Jakub Wilk discovered two instances in tag.py where temporary files were created insecurely via mktemp(). A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file.
Further details are available in the original report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737062