Use case
With the ongoing efforts of pooling the codebase in the current pyoaev client and the future SDK, raising the quality and security assessments on this project/those projects is becoming even more relevant and profitable.
Current workaround
Locally run SAST or used the run made with snyk on other projects using pyoaev.
Proposed solution
Starting the new CI step with PyCQA/bandit before investigating other options in a follow-up (e.g. snyk, CodeQL, bearer, semgrep, skylos, etc.)
Additional information
As of today, running bandit on ./pyoaev, ./scripts and ./test for medium and high severity returns:
- [CWE-20] the use of the unsafe native
yaml.load function (as pointed out by the Python documentation too)
- [CWE-295] the use of
_create_unverified_context of the ssl library
- [CWE-78] the use of
os.system (instead of subprocess or non-shell alternatives) *3
- [CWE-400] the lack of
timeout value for requests
This feedback is relevant for either quality or security reasons, thus even though bandit may not be the best choice we could make (I just don't know and don't want to decide for the whole team), it could be a valuable first step
If the feature request is approved, would you be willing to submit a PR?
Yes / No (help can be provided if you need assistance submitting a PR)
Use case
With the ongoing efforts of pooling the codebase in the current
pyoaevclient and the future SDK, raising the quality and security assessments on this project/those projects is becoming even more relevant and profitable.Current workaround
Locally run SAST or used the run made with snyk on other projects using
pyoaev.Proposed solution
Starting the new CI step with
PyCQA/banditbefore investigating other options in a follow-up (e.g. snyk, CodeQL, bearer, semgrep, skylos, etc.)Additional information
As of today, running
banditon./pyoaev,./scriptsand./testfor medium and high severity returns:yaml.loadfunction (as pointed out by the Python documentation too)_create_unverified_contextof the ssl libraryos.system(instead ofsubprocessor non-shell alternatives) *3timeoutvalue for requestsThis feedback is relevant for either quality or security reasons, thus even though
banditmay not be the best choice we could make (I just don't know and don't want to decide for the whole team), it could be a valuable first stepIf the feature request is approved, would you be willing to submit a PR?
Yes / No (help can be provided if you need assistance submitting a PR)