summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorIan Cordasco <graffatcolmingov@gmail.com>2016-06-14 07:58:13 -0500
committerIan Cordasco <graffatcolmingov@gmail.com>2016-06-14 07:58:13 -0500
commitdc8fc0058d638479335b30e441973f7eab2ac2b0 (patch)
tree0444825825f7705f26db36010fc94e7422f5ea40
parent6dca1d6fd74c61be16d95bd37dab58cc5e91d033 (diff)
downloadflake8-dc8fc0058d638479335b30e441973f7eab2ac2b0.tar.gz
Configure bandit to ignore subprocess warnings
-rw-r--r--.bandit.yml84
-rw-r--r--tox.ini2
2 files changed, 85 insertions, 1 deletions
diff --git a/.bandit.yml b/.bandit.yml
new file mode 100644
index 0000000..ea868e2
--- /dev/null
+++ b/.bandit.yml
@@ -0,0 +1,84 @@
+tests:
+skips:
+- B404 # Ignore warnings about importing subprocess
+- B603 # Ignore warnings about calling subprocess.Popen without shell=True
+- B607 # Ignore warnings about calling subprocess.Popen without a full path to executable
+
+### (optional) plugin settings - some test plugins require configuration data
+### that may be given here, per-plugin. All bandit test plugins have a built in
+### set of sensible defaults and these will be used if no configuration is
+### provided. It is not necessary to provide settings for every (or any) plugin
+### if the defaults are acceptable.
+
+any_other_function_with_shell_equals_true:
+ no_shell: [os.execl, os.execle, os.execlp, os.execlpe, os.execv, os.execve, os.execvp,
+ os.execvpe, os.spawnl, os.spawnle, os.spawnlp, os.spawnlpe, os.spawnv, os.spawnve,
+ os.spawnvp, os.spawnvpe, os.startfile]
+ shell: [os.system, os.popen, os.popen2, os.popen3, os.popen4, popen2.popen2, popen2.popen3,
+ popen2.popen4, popen2.Popen3, popen2.Popen4, commands.getoutput, commands.getstatusoutput]
+ subprocess: [subprocess.Popen, subprocess.call, subprocess.check_call, subprocess.check_output,
+ utils.execute, utils.execute_with_timeout]
+execute_with_run_as_root_equals_true:
+ function_names: [ceilometer.utils.execute, cinder.utils.execute, neutron.agent.linux.utils.execute,
+ nova.utils.execute, nova.utils.trycmd]
+hardcoded_tmp_directory:
+ tmp_dirs: [/tmp, /var/tmp, /dev/shm]
+linux_commands_wildcard_injection:
+ no_shell: [os.execl, os.execle, os.execlp, os.execlpe, os.execv, os.execve, os.execvp,
+ os.execvpe, os.spawnl, os.spawnle, os.spawnlp, os.spawnlpe, os.spawnv, os.spawnve,
+ os.spawnvp, os.spawnvpe, os.startfile]
+ shell: [os.system, os.popen, os.popen2, os.popen3, os.popen4, popen2.popen2, popen2.popen3,
+ popen2.popen4, popen2.Popen3, popen2.Popen4, commands.getoutput, commands.getstatusoutput]
+ subprocess: [subprocess.Popen, subprocess.call, subprocess.check_call, subprocess.check_output,
+ utils.execute, utils.execute_with_timeout]
+password_config_option_not_marked_secret:
+ function_names: [oslo.config.cfg.StrOpt, oslo_config.cfg.StrOpt]
+ssl_with_bad_defaults:
+ bad_protocol_versions: [PROTOCOL_SSLv2, SSLv2_METHOD, SSLv23_METHOD, PROTOCOL_SSLv3,
+ PROTOCOL_TLSv1, SSLv3_METHOD, TLSv1_METHOD]
+ssl_with_bad_version:
+ bad_protocol_versions: [PROTOCOL_SSLv2, SSLv2_METHOD, SSLv23_METHOD, PROTOCOL_SSLv3,
+ PROTOCOL_TLSv1, SSLv3_METHOD, TLSv1_METHOD]
+start_process_with_a_shell:
+ no_shell: [os.execl, os.execle, os.execlp, os.execlpe, os.execv, os.execve, os.execvp,
+ os.execvpe, os.spawnl, os.spawnle, os.spawnlp, os.spawnlpe, os.spawnv, os.spawnve,
+ os.spawnvp, os.spawnvpe, os.startfile]
+ shell: [os.system, os.popen, os.popen2, os.popen3, os.popen4, popen2.popen2, popen2.popen3,
+ popen2.popen4, popen2.Popen3, popen2.Popen4, commands.getoutput, commands.getstatusoutput]
+ subprocess: [subprocess.Popen, subprocess.call, subprocess.check_call, subprocess.check_output,
+ utils.execute, utils.execute_with_timeout]
+start_process_with_no_shell:
+ no_shell: [os.execl, os.execle, os.execlp, os.execlpe, os.execv, os.execve, os.execvp,
+ os.execvpe, os.spawnl, os.spawnle, os.spawnlp, os.spawnlpe, os.spawnv, os.spawnve,
+ os.spawnvp, os.spawnvpe, os.startfile]
+ shell: [os.system, os.popen, os.popen2, os.popen3, os.popen4, popen2.popen2, popen2.popen3,
+ popen2.popen4, popen2.Popen3, popen2.Popen4, commands.getoutput, commands.getstatusoutput]
+ subprocess: [subprocess.Popen, subprocess.call, subprocess.check_call, subprocess.check_output,
+ utils.execute, utils.execute_with_timeout]
+start_process_with_partial_path:
+ no_shell: [os.execl, os.execle, os.execlp, os.execlpe, os.execv, os.execve, os.execvp,
+ os.execvpe, os.spawnl, os.spawnle, os.spawnlp, os.spawnlpe, os.spawnv, os.spawnve,
+ os.spawnvp, os.spawnvpe, os.startfile]
+ shell: [os.system, os.popen, os.popen2, os.popen3, os.popen4, popen2.popen2, popen2.popen3,
+ popen2.popen4, popen2.Popen3, popen2.Popen4, commands.getoutput, commands.getstatusoutput]
+ subprocess: [subprocess.Popen, subprocess.call, subprocess.check_call, subprocess.check_output,
+ utils.execute, utils.execute_with_timeout]
+subprocess_popen_with_shell_equals_true:
+ no_shell: [os.execl, os.execle, os.execlp, os.execlpe, os.execv, os.execve, os.execvp,
+ os.execvpe, os.spawnl, os.spawnle, os.spawnlp, os.spawnlpe, os.spawnv, os.spawnve,
+ os.spawnvp, os.spawnvpe, os.startfile]
+ shell: [os.system, os.popen, os.popen2, os.popen3, os.popen4, popen2.popen2, popen2.popen3,
+ popen2.popen4, popen2.Popen3, popen2.Popen4, commands.getoutput, commands.getstatusoutput]
+ subprocess: [subprocess.Popen, subprocess.call, subprocess.check_call, subprocess.check_output,
+ utils.execute, utils.execute_with_timeout]
+subprocess_without_shell_equals_true:
+ no_shell: [os.execl, os.execle, os.execlp, os.execlpe, os.execv, os.execve, os.execvp,
+ os.execvpe, os.spawnl, os.spawnle, os.spawnlp, os.spawnlpe, os.spawnv, os.spawnve,
+ os.spawnvp, os.spawnvpe, os.startfile]
+ shell: [os.system, os.popen, os.popen2, os.popen3, os.popen4, popen2.popen2, popen2.popen3,
+ popen2.popen4, popen2.Popen3, popen2.Popen4, commands.getoutput, commands.getstatusoutput]
+ subprocess: [subprocess.Popen, subprocess.call, subprocess.check_call, subprocess.check_output,
+ utils.execute, utils.execute_with_timeout]
+try_except_continue: {check_typed_exception: false}
+try_except_pass: {check_typed_exception: false}
+
diff --git a/tox.ini b/tox.ini
index 045abb6..0bc1795 100644
--- a/tox.ini
+++ b/tox.ini
@@ -66,7 +66,7 @@ use_develop = false
deps =
bandit
commands =
- bandit -r flake8/
+ bandit -r flake8/ -c .bandit.yml
[testenv:linters]
basepython = python3