From ec9e5eff61d5b723a832b2a248b312430ebb85c7 Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 14 Jun 2026 10:58:02 +0200 Subject: [PATCH] chore(tests): silence bandit B104 on redaction-sentinel asserts The two "0.0.0.0" comparisons in test_support_helpers verify the support-bundle net.info[*].ip redaction sentinel (mirrors the support.py:1193 annotation), not a socket bind. Annotate inline. --- backend/tests/unit/test_support_helpers.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/backend/tests/unit/test_support_helpers.py b/backend/tests/unit/test_support_helpers.py index b9afa079c..d717d457c 100644 --- a/backend/tests/unit/test_support_helpers.py +++ b/backend/tests/unit/test_support_helpers.py @@ -1166,8 +1166,8 @@ class TestRedactRawPushStatus: out = _redact_raw_push_status(raw) # LAN topology must be scrubbed (mirrors the #1429 VP fix). - assert out["net"]["info"][0]["ip"] == "0.0.0.0" - assert out["net"]["info"][1]["ip"] == "0.0.0.0" + assert out["net"]["info"][0]["ip"] == "0.0.0.0" # nosec B104 - redaction sentinel, not a bind address + assert out["net"]["info"][1]["ip"] == "0.0.0.0" # nosec B104 - redaction sentinel, not a bind address # Non-IP siblings inside the entry survive so the shape stays # diagnosable (interface count, mask presence, etc.). assert out["net"]["info"][0]["mask"] == "255.255.255.0"