From eb98521e93722fa414acea5ed7174cb9d465350c Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 24 May 2026 12:02:49 +0200 Subject: [PATCH] fix(test): use /nonexistent/ instead of /tmp/ to satisfy Bandit B108 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The test_returns_empty_when_3mf_missing test sets a deliberately non-existent file_path on a PrintArchive to verify compute_deficit_for_queue_item handles the missing-3MF branch gracefully. The path just needs to fail an existence check — the /tmp/ prefix was incidental. Bandit B108 ("insecure temp file usage") regex-matches /tmp/, /var/tmp/, and /dev/shm/. Dropping /tmp/ in favour of /nonexistent/ keeps the test behaviour identical (still a guaranteed-missing path, still triggers the missing-file branch) while clearing the GitHub Advanced Security finding on PR #1514 without adding a # nosec annotation. --- backend/tests/unit/services/test_filament_deficit.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/tests/unit/services/test_filament_deficit.py b/backend/tests/unit/services/test_filament_deficit.py index 0df1d8d57..3cdb52106 100644 --- a/backend/tests/unit/services/test_filament_deficit.py +++ b/backend/tests/unit/services/test_filament_deficit.py @@ -223,7 +223,7 @@ class TestFilamentDeficit: printer = await printer_factory() archive = PrintArchive( filename="ghost.3mf", - file_path="/tmp/nope-does-not-exist.3mf", + file_path="/nonexistent/ghost.3mf", file_size=0, status="completed", )