chore(tooling): enable flake8-bandit rules

Turns on ruff's S rules, which matter for code that shells out to ffmpeg,
aria2c and yt-dlp. S607 is ignored project-wide: binaries are looked up on
PATH deliberately and preflight-checked with shutil.which, so hardcoding
absolute paths would be less portable rather than safer.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-13 14:17:41 -05:00
co-authored by Claude Opus 5
parent 5042d73770
commit 15a28495b8
3 changed files with 11 additions and 4 deletions
+8 -2
View File
@@ -41,10 +41,16 @@ src = ["src", "tests"]
extend-exclude = ["*.md"]
[tool.ruff.lint]
select = ["E", "F", "W", "I", "N", "UP", "B", "A", "C4", "SIM", "PTH", "RET", "ARG", "TID", "TC", "RUF"]
select = ["E", "F", "W", "I", "N", "UP", "B", "A", "C4", "SIM", "PTH", "RET", "ARG", "TID", "TC", "RUF", "S"]
# S607: binaries are looked up on PATH on purpose and preflight-checked with
# shutil.which; hardcoding absolute paths would be less portable, not safer.
ignore = ["S607"]
[tool.ruff.lint.per-file-ignores]
"tests/*" = ["ARG001", "ARG002"]
# S101: asserts are the point of a test file.
"tests/*" = ["ARG001", "ARG002", "S101"]
# Throwaway benchmarks, not pipeline code.
"scripts/*" = ["S603"]
[tool.pyright]
include = ["src", "tests"]
+2 -1
View File
@@ -35,7 +35,8 @@ REQUIRED_BINARIES = ("ffmpeg", "ffprobe")
def _run(args: list[str], *, check: bool = True) -> subprocess.CompletedProcess[bytes]:
try:
return subprocess.run(args, capture_output=True, check=check)
# Argument lists are built here from fixed templates; never a shell string.
return subprocess.run(args, capture_output=True, check=check) # noqa: S603
except FileNotFoundError as exc:
raise errors.PreflightError(
f"{args[0]} is not installed or not on PATH",
+1 -1
View File
@@ -10,7 +10,7 @@ if TYPE_CHECKING:
def _run(args: list[str]) -> None:
subprocess.run(args, capture_output=True, check=True)
subprocess.run(args, capture_output=True, check=True) # noqa: S603
@pytest.fixture(scope="session")