GRM-24: fix: resolve bandit security warnings in source code and tests
This commit is contained in:
+3
-3
@@ -6,7 +6,7 @@ Usage:
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
import os
|
import os
|
||||||
import subprocess
|
import subprocess # nosec B404
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
import click
|
import click
|
||||||
@@ -19,7 +19,7 @@ from gitea_runner_manager.i18n import _
|
|||||||
|
|
||||||
def build_package() -> None:
|
def build_package() -> None:
|
||||||
"""Build the Python package using python -m build."""
|
"""Build the Python package using python -m build."""
|
||||||
result = subprocess.run(
|
result = subprocess.run( # nosec B603
|
||||||
[sys.executable, "-m", "build"],
|
[sys.executable, "-m", "build"],
|
||||||
capture_output=True,
|
capture_output=True,
|
||||||
text=True,
|
text=True,
|
||||||
@@ -36,7 +36,7 @@ def build_package() -> None:
|
|||||||
|
|
||||||
def publish_to_pypi(token: str) -> None:
|
def publish_to_pypi(token: str) -> None:
|
||||||
"""Publish built packages to PyPI using twine."""
|
"""Publish built packages to PyPI using twine."""
|
||||||
result = subprocess.run(
|
result = subprocess.run( # nosec B603
|
||||||
[
|
[
|
||||||
sys.executable,
|
sys.executable,
|
||||||
"-m",
|
"-m",
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ Rules:
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
import re
|
import re
|
||||||
import subprocess
|
import subprocess # nosec B404
|
||||||
|
|
||||||
import click
|
import click
|
||||||
|
|
||||||
@@ -24,7 +24,7 @@ def first_line(text: str) -> str:
|
|||||||
|
|
||||||
def get_branch() -> str:
|
def get_branch() -> str:
|
||||||
try:
|
try:
|
||||||
result = subprocess.run(
|
result = subprocess.run( # nosec
|
||||||
["git", "symbolic-ref", "--short", "HEAD"],
|
["git", "symbolic-ref", "--short", "HEAD"],
|
||||||
capture_output=True,
|
capture_output=True,
|
||||||
text=True,
|
text=True,
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ from __future__ import annotations
|
|||||||
import logging
|
import logging
|
||||||
import os
|
import os
|
||||||
import re
|
import re
|
||||||
import subprocess
|
import subprocess # nosec B404
|
||||||
import sys
|
import sys
|
||||||
from datetime import datetime
|
from datetime import datetime
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
@@ -62,14 +62,14 @@ class AnsibleExecutor:
|
|||||||
"""Execute command, streaming stdout+stderr to log file. Returns exit code."""
|
"""Execute command, streaming stdout+stderr to log file. Returns exit code."""
|
||||||
env = os.environ.copy()
|
env = os.environ.copy()
|
||||||
with open(log_file, "a") as f:
|
with open(log_file, "a") as f:
|
||||||
proc = subprocess.Popen(
|
proc = subprocess.Popen( # nosec B603
|
||||||
cmd,
|
cmd,
|
||||||
env=env,
|
env=env,
|
||||||
stdout=subprocess.PIPE,
|
stdout=subprocess.PIPE,
|
||||||
stderr=subprocess.STDOUT,
|
stderr=subprocess.STDOUT,
|
||||||
text=True,
|
text=True,
|
||||||
)
|
)
|
||||||
assert proc.stdout is not None
|
assert proc.stdout is not None # nosec B101
|
||||||
try:
|
try:
|
||||||
for line in proc.stdout:
|
for line in proc.stdout:
|
||||||
f.write(line)
|
f.write(line)
|
||||||
@@ -108,7 +108,7 @@ class AnsibleExecutor:
|
|||||||
cmd.append("--ask-become-pass")
|
cmd.append("--ask-become-pass")
|
||||||
|
|
||||||
env = os.environ.copy()
|
env = os.environ.copy()
|
||||||
proc = subprocess.run(
|
proc = subprocess.run( # nosec B603
|
||||||
cmd,
|
cmd,
|
||||||
env=env,
|
env=env,
|
||||||
capture_output=True,
|
capture_output=True,
|
||||||
@@ -137,6 +137,6 @@ class AnsibleExecutor:
|
|||||||
)
|
)
|
||||||
if match:
|
if match:
|
||||||
return match.group(1).replace("\\n", " ").strip()
|
return match.group(1).replace("\\n", " ").strip()
|
||||||
except Exception:
|
except OSError:
|
||||||
pass
|
return None
|
||||||
return None
|
return None
|
||||||
|
|||||||
@@ -330,7 +330,7 @@ class RunnerManager:
|
|||||||
ask_become_pass=True,
|
ask_become_pass=True,
|
||||||
check=False,
|
check=False,
|
||||||
)
|
)
|
||||||
except Exception:
|
except AnsibleError:
|
||||||
continue
|
continue
|
||||||
status = self._parse_status(stdout)
|
status = self._parse_status(stdout)
|
||||||
if status != "unknown":
|
if status != "unknown":
|
||||||
@@ -351,7 +351,7 @@ class RunnerManager:
|
|||||||
check=False,
|
check=False,
|
||||||
)
|
)
|
||||||
service_status = self._parse_status(stdout)
|
service_status = self._parse_status(stdout)
|
||||||
except Exception:
|
except AnsibleError:
|
||||||
service_status = "unknown"
|
service_status = "unknown"
|
||||||
else:
|
else:
|
||||||
try:
|
try:
|
||||||
@@ -366,7 +366,7 @@ class RunnerManager:
|
|||||||
check=False,
|
check=False,
|
||||||
)
|
)
|
||||||
service_status = self._parse_status(stdout)
|
service_status = self._parse_status(stdout)
|
||||||
except Exception:
|
except AnsibleError:
|
||||||
service_status = "unknown"
|
service_status = "unknown"
|
||||||
# Translate known status values
|
# Translate known status values
|
||||||
translated_status = _(
|
translated_status = _(
|
||||||
|
|||||||
@@ -518,7 +518,7 @@ class TestRunnerManager:
|
|||||||
}
|
}
|
||||||
manager = RunnerManager(registry=mock_registry)
|
manager = RunnerManager(registry=mock_registry)
|
||||||
mock_executor = MagicMock()
|
mock_executor = MagicMock()
|
||||||
mock_executor.run_ad_hoc.side_effect = Exception("ssh fail")
|
mock_executor.run_ad_hoc.side_effect = AnsibleError("ssh fail")
|
||||||
manager._executor = mock_executor
|
manager._executor = mock_executor
|
||||||
|
|
||||||
runners = manager.list_runners()
|
runners = manager.list_runners()
|
||||||
@@ -579,7 +579,7 @@ class TestRunnerManager:
|
|||||||
}
|
}
|
||||||
manager = RunnerManager(registry=mock_registry)
|
manager = RunnerManager(registry=mock_registry)
|
||||||
mock_executor = MagicMock()
|
mock_executor = MagicMock()
|
||||||
mock_executor.run_ad_hoc.side_effect = [Exception("ssh fail"), "running"]
|
mock_executor.run_ad_hoc.side_effect = [AnsibleError("ssh fail"), "running"]
|
||||||
manager._executor = mock_executor
|
manager._executor = mock_executor
|
||||||
|
|
||||||
runners = manager.list_runners()
|
runners = manager.list_runners()
|
||||||
@@ -593,7 +593,7 @@ class TestRunnerManager:
|
|||||||
}
|
}
|
||||||
manager = RunnerManager(registry=mock_registry)
|
manager = RunnerManager(registry=mock_registry)
|
||||||
mock_executor = MagicMock()
|
mock_executor = MagicMock()
|
||||||
mock_executor.run_ad_hoc.side_effect = Exception("ssh fail")
|
mock_executor.run_ad_hoc.side_effect = AnsibleError("ssh fail")
|
||||||
manager._executor = mock_executor
|
manager._executor = mock_executor
|
||||||
|
|
||||||
runners = manager.list_runners()
|
runners = manager.list_runners()
|
||||||
|
|||||||
Reference in New Issue
Block a user