Skip to content

ci(client-python): adding PyCQA/bandit step to the CI for improved code quality/security (SATS quickwin) #355

Description

@guzmud

Use case

With the ongoing efforts of pooling the codebase in the current pyoaev client and the future SDK, raising the quality and security assessments on this project/those projects is becoming even more relevant and profitable.

Current workaround

Locally run SAST or used the run made with snyk on other projects using pyoaev.

Proposed solution

Starting the new CI step with PyCQA/bandit before investigating other options in a follow-up (e.g. snyk, CodeQL, bearer, semgrep, skylos, etc.)

Additional information

As of today, running bandit on ./pyoaev, ./scripts and ./test for medium and high severity returns:

  • [CWE-20] the use of the unsafe native yaml.load function (as pointed out by the Python documentation too)
  • [CWE-295] the use of _create_unverified_context of the ssl library
  • [CWE-78] the use of os.system (instead of subprocess or non-shell alternatives) *3
  • [CWE-400] the lack of timeout value for requests

This feedback is relevant for either quality or security reasons, thus even though bandit may not be the best choice we could make (I just don't know and don't want to decide for the whole team), it could be a valuable first step

If the feature request is approved, would you be willing to submit a PR?

Yes / No (help can be provided if you need assistance submitting a PR)

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureType: new feature or capability (feat:).needs triageNeeds triage from the Filigran product team.tech foundationLinked to tech foundation.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions