chore(tooling): enable flake8-bandit rules
Turns on ruff's S rules, which matter for code that shells out to ffmpeg, aria2c and yt-dlp. S607 is ignored project-wide: binaries are looked up on PATH deliberately and preflight-checked with shutil.which, so hardcoding absolute paths would be less portable rather than safer. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
+8
-2
@@ -41,10 +41,16 @@ src = ["src", "tests"]
|
||||
extend-exclude = ["*.md"]
|
||||
|
||||
[tool.ruff.lint]
|
||||
select = ["E", "F", "W", "I", "N", "UP", "B", "A", "C4", "SIM", "PTH", "RET", "ARG", "TID", "TC", "RUF"]
|
||||
select = ["E", "F", "W", "I", "N", "UP", "B", "A", "C4", "SIM", "PTH", "RET", "ARG", "TID", "TC", "RUF", "S"]
|
||||
# S607: binaries are looked up on PATH on purpose and preflight-checked with
|
||||
# shutil.which; hardcoding absolute paths would be less portable, not safer.
|
||||
ignore = ["S607"]
|
||||
|
||||
[tool.ruff.lint.per-file-ignores]
|
||||
"tests/*" = ["ARG001", "ARG002"]
|
||||
# S101: asserts are the point of a test file.
|
||||
"tests/*" = ["ARG001", "ARG002", "S101"]
|
||||
# Throwaway benchmarks, not pipeline code.
|
||||
"scripts/*" = ["S603"]
|
||||
|
||||
[tool.pyright]
|
||||
include = ["src", "tests"]
|
||||
|
||||
@@ -35,7 +35,8 @@ REQUIRED_BINARIES = ("ffmpeg", "ffprobe")
|
||||
|
||||
def _run(args: list[str], *, check: bool = True) -> subprocess.CompletedProcess[bytes]:
|
||||
try:
|
||||
return subprocess.run(args, capture_output=True, check=check)
|
||||
# Argument lists are built here from fixed templates; never a shell string.
|
||||
return subprocess.run(args, capture_output=True, check=check) # noqa: S603
|
||||
except FileNotFoundError as exc:
|
||||
raise errors.PreflightError(
|
||||
f"{args[0]} is not installed or not on PATH",
|
||||
|
||||
+1
-1
@@ -10,7 +10,7 @@ if TYPE_CHECKING:
|
||||
|
||||
|
||||
def _run(args: list[str]) -> None:
|
||||
subprocess.run(args, capture_output=True, check=True)
|
||||
subprocess.run(args, capture_output=True, check=True) # noqa: S603
|
||||
|
||||
|
||||
@pytest.fixture(scope="session")
|
||||
|
||||
Reference in New Issue
Block a user