Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -111,5 +111,5 @@ jobs:
with:
python-version: ${{ matrix.python-version }}

- name: Run security checks (bandit + safety)
- name: Run security checks (bandit + uv audit)
run: uvx nox -s security_test
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -289,7 +289,7 @@ file again.

ty type-checks the generated code too; the benchmarks assert the
generated method stays within 15 % of an equivalent hand-written `httpx2` call; the security
session runs bandit and safety as in CI; the sandbox runner sends every
session runs bandit and `uv audit` as in CI; the sandbox runner sends every
operation its embedded examples. The last two lines regenerate the SDK after a
spec bump (Node 24) and run the generator's own vitest suite and type check.

Expand Down
2 changes: 1 addition & 1 deletion docs/UPDATING_SPECS.md
Original file line number Diff line number Diff line change
Expand Up @@ -87,7 +87,7 @@ Look at:
uv run ruff check src tests benchmarks && uv run ruff format --check src tests benchmarks
uv run ty check
uv run pytest
uvx nox -s security_test # bandit over the package (generated code included) + safety
uvx nox -s security_test # bandit over the package (generated code included) + uv audit
uv run python -m tests.sandbox # every operation against its embedded examples
```

Expand Down
8 changes: 2 additions & 6 deletions noxfile.py
Original file line number Diff line number Diff line change
Expand Up @@ -27,11 +27,7 @@ def type_check(session: nox.Session) -> None:

@nox.session
def security_test(session: nox.Session) -> None:
"""bandit over the package (generated code included) and safety over the locked dependencies."""
"""bandit over the package (generated code included) and uv audit over locked dependencies."""
session.install(".[security-test]")
session.run("bandit", "-q", "-r", "src/amzn_selling_partner/")
# SFTY-20260721-58460 flags every setuptools release below 83.0.0, but 83+ removed
# `pkg_resources`, which safety==2.3.4 itself still requires to run. setuptools is a
# dev-only build tool here (not a runtime dependency of the published package), so the
# finding is ignored until safety can run without pkg_resources.
session.run("safety", "check", "--ignore", "SFTY-20260721-58460")
session.run("uv", "audit", "--locked")
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ dev = [
"ruff>=0.16",
"pytest-benchmark>=5",
]
security-test = ["bandit==1.9.4", "safety==3.8.1", "setuptools<81"]
security-test = ["bandit==1.9.4"]

[build-system]
requires = ["uv_build>=0.8,<0.13"]
Expand Down
Loading
Loading