Skip to content

ci(client-python): adding bandit as a sats quickwin (#355) - #357

Open
Ferdinand (guzmud) wants to merge 1 commit into
mainfrom
ci/355-bandit-sats-quickwin
Open

Ferdinand (guzmud) wants to merge 1 commit into
mainfrom
ci/355-bandit-sats-quickwin

Conversation

@guzmud

@guzmud Ferdinand (guzmud) commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Proposed changes

  • Adding non-blocking step that runs bandit on the code

Testing Instructions

  1. Step-by-step how to test
  2. Environment or config notes

Related issues

Checklist

  • I consider the submitted work as finished
  • I tested the code for its functionality
  • I wrote test cases for the relevant uses case
  • I added/update the relevant documentation (either on github or on notion)
  • Where necessary I refactored code to improve the overall quality
  • For bug fix -> I implemented a test that covers the bug

Further comments

Copilot AI balanced review requested due to automatic review settings October 8, 2026 13:05
@github-actions github-actions Bot added the filigran team Item from the Filigran team. label Oct 8, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The scan cannot locate Bandit and is blocking despite being described as non-blocking.

2 open findings
What changed in this PR

Adds Bandit security analysis to CI for the Python client.

Changes:

  • Runs Bandit against application, script, and test code.
  • Triggers analysis for pull requests and pushes to main.
File Description
.github/​workflows/​sats-analysis.yml Defines the Bandit analysis workflow.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread .github/workflows/sats-analysis.yml Outdated
Comment thread .github/workflows/sats-analysis.yml
@guzmud
Ferdinand (guzmud) force-pushed the ci/355-bandit-sats-quickwin branch from 2ae9eef to 91338a8 Compare October 8, 2026 13:14
@guzmud Ferdinand (guzmud) changed the title ci(355): adding bandit as a sats quickwin (#355) ci(client-python): adding bandit as a sats quickwin (#355) Oct 8, 2026
@guzmud
Ferdinand (guzmud) force-pushed the ci/355-bandit-sats-quickwin branch from 91338a8 to 4ef7a5b Compare October 8, 2026 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

filigran team Item from the Filigran team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci(client-python): adding PyCQA/bandit step to the CI for improved code quality/security (SATS quickwin)

2 participants