Fix safe security findings: hashlib, log injection, broad excepts

- Add usedforsecurity=False to MD5 (AMS fingerprint) and SHA1 (git blob
  hash) calls to silence Bandit B303 / CodeQL weak-crypto findings
- Convert ~996 f-string logging calls to parameterized %s-style across
  55 files to prevent log injection (Bandit G201 / CodeQL log-injection)
- Narrow ~199 broad except Exception blocks to specific types:
  OperationalError for DB migrations, OSError for network/file cleanup,
  (OSError, ftplib.error_reply) for FTP, and targeted tuples for
  ZIP/XML/JSON parsing — 36 intentionally left broad (mixed async,
  re-raise patterns)
This commit is contained in:
maziggy
2026-02-06 11:37:59 +01:00
parent 91662d9c5d
commit 53bd4fadb3
60 changed files with 1732 additions and 1284 deletions
+3
View File
@@ -61,3 +61,6 @@ data/
# JWT secret file (should be in data dir, but protect project root too)
.jwt_secret
# Security scan output
*.sarif