From 15a28495b8858c1b62b42ea755fb2f034d1965c3 Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Sun, 13 Sep 2026 14:17:41 -0500 Subject: [PATCH] chore(tooling): enable flake8-bandit rules Turns on ruff's S rules, which matter for code that shells out to ffmpeg, aria2c and yt-dlp. S607 is ignored project-wide: binaries are looked up on PATH deliberately and preflight-checked with shutil.which, so hardcoding absolute paths would be less portable rather than safer. Co-Authored-By: Claude Opus 5 (1M context) --- pyproject.toml | 10 ++++++++-- src/ccn_transcribe/media/ffmpeg.py | 3 ++- tests/conftest.py | 2 +- 3 files changed, 11 insertions(+), 4 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index 6751e32..1799f82 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -41,10 +41,16 @@ src = ["src", "tests"] extend-exclude = ["*.md"] [tool.ruff.lint] -select = ["E", "F", "W", "I", "N", "UP", "B", "A", "C4", "SIM", "PTH", "RET", "ARG", "TID", "TC", "RUF"] +select = ["E", "F", "W", "I", "N", "UP", "B", "A", "C4", "SIM", "PTH", "RET", "ARG", "TID", "TC", "RUF", "S"] +# S607: binaries are looked up on PATH on purpose and preflight-checked with +# shutil.which; hardcoding absolute paths would be less portable, not safer. +ignore = ["S607"] [tool.ruff.lint.per-file-ignores] -"tests/*" = ["ARG001", "ARG002"] +# S101: asserts are the point of a test file. +"tests/*" = ["ARG001", "ARG002", "S101"] +# Throwaway benchmarks, not pipeline code. +"scripts/*" = ["S603"] [tool.pyright] include = ["src", "tests"] diff --git a/src/ccn_transcribe/media/ffmpeg.py b/src/ccn_transcribe/media/ffmpeg.py index dbce174..ceb40d7 100644 --- a/src/ccn_transcribe/media/ffmpeg.py +++ b/src/ccn_transcribe/media/ffmpeg.py @@ -35,7 +35,8 @@ REQUIRED_BINARIES = ("ffmpeg", "ffprobe") def _run(args: list[str], *, check: bool = True) -> subprocess.CompletedProcess[bytes]: try: - return subprocess.run(args, capture_output=True, check=check) + # Argument lists are built here from fixed templates; never a shell string. + return subprocess.run(args, capture_output=True, check=check) # noqa: S603 except FileNotFoundError as exc: raise errors.PreflightError( f"{args[0]} is not installed or not on PATH", diff --git a/tests/conftest.py b/tests/conftest.py index 24ce174..eae905f 100644 --- a/tests/conftest.py +++ b/tests/conftest.py @@ -10,7 +10,7 @@ if TYPE_CHECKING: def _run(args: list[str]) -> None: - subprocess.run(args, capture_output=True, check=True) + subprocess.run(args, capture_output=True, check=True) # noqa: S603 @pytest.fixture(scope="session")