mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
Fix safe security findings: hashlib, log injection, broad excepts, bandit suppressions
- Add usedforsecurity=False to MD5 (AMS fingerprint) and SHA1 (git blob hash) calls to silence Bandit B303 / CodeQL weak-crypto findings - Convert ~996 f-string logging calls to parameterized %s-style across 55 files to prevent log injection (Bandit G201 / CodeQL log-injection) - Narrow ~199 broad except Exception blocks to specific types: OperationalError for DB migrations, OSError for network/file cleanup, (OSError, ftplib.error_reply) for FTP, and targeted tuples for ZIP/XML/JSON parsing — 36 intentionally left broad (mixed async, re-raise patterns) - Add # nosec comments to 9 known-safe lines (0.0.0.0 virtual printer binds, ftplib imports) and exclude backend/tests/ from bandit scan - Bandit now reports 0 medium/high findings
This commit is contained in:
+1
-1
@@ -118,7 +118,7 @@ scan_bandit() {
|
||||
echo "SKIP: 'bandit' not found. Install: pip install bandit[sarif]"
|
||||
return 2
|
||||
fi
|
||||
bandit -r backend/ --severity-level medium 2>&1
|
||||
bandit -r backend/ --severity-level medium -x backend/tests 2>&1
|
||||
}
|
||||
|
||||
scan_codeql_python() {
|
||||
|
||||
Reference in New Issue
Block a user