diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index cad2c21..a07f5af 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -63,6 +63,19 @@ repos: args: - --select=E9,F63,F7,F82 + - repo: https://github.com/PyCQA/bandit + rev: 1.9.4 + hooks: + # Critical mandatory checks from QGIS plugin repository that prevent publishing a new version of the plugin + # NOTE: Ruff uses `S` and Bandit `B` prefixes, so both codes must be excluded per line. + # Keep in sync with https://github.com/qgis/QGIS-Plugins-Website/blob/master/qgis-app/plugins/management/commands/data/bandit_rules.json + - id: bandit + args: [ + "-t", "B102,B103,B105,B106,B107,B201,B202,B301,B302,B304,B305,B306,B307,B312,B321,B323,B401,B402,B412,B413,B501,B502,B503,B505,B506,B507,B601,B602,B604,B605,B609,B610,B611,B612,B613,B701", + "-x", "./.venv,./venv,./.cache,./build,./dist", + "-r", ".", + ] + ci: autofix_prs: true autoupdate_schedule: quarterly diff --git a/test/test_gui.py b/test/test_gui.py index d8ac6e3..f451749 100644 --- a/test/test_gui.py +++ b/test/test_gui.py @@ -144,14 +144,14 @@ def test_display_role_value(self): self.assertEqual(m.data(idx, QtCore.Qt.ItemDataRole.DisplayRole), "localhost") def test_password_masked_in_display(self): - m = self._make_model(config={"password": "secret"}) + m = self._make_model(config={"password": "secret"}) # nosec B105 idx = m.index(0, 1) display = m.data(idx, QtCore.Qt.ItemDataRole.DisplayRole) self.assertNotEqual(display, "secret") self.assertEqual(display, "************") def test_password_visible_in_edit_role(self): - m = self._make_model(config={"password": "secret"}) + m = self._make_model(config={"password": "secret"}) # nosec B105 idx = m.index(0, 1) self.assertEqual(m.data(idx, QtCore.Qt.ItemDataRole.EditRole), "secret") diff --git a/test/test_lib.py b/test/test_lib.py index b109b32..73adde4 100644 --- a/test/test_lib.py +++ b/test/test_lib.py @@ -79,7 +79,14 @@ def test_service_config(self): conf = service_config("service_1") self.assertEqual( - conf, {"host": "host_1", "dbname": "db_1", "port": "1111", "user": "user_1", "password": "pwd_1"} + conf, + { + "host": "host_1", + "dbname": "db_1", + "port": "1111", + "user": "user_1", + "password": "pwd_1", # nosec B105 + }, ) def test_write_service_setting(self): @@ -114,7 +121,14 @@ def test_write_service(self): # Overwrite the whole service_3 config using service_2 params config_3 = service_config("service_3") self.assertEqual( - config_3, {"host": "host_3", "dbname": "db_3", "port": "3333", "user": "user_3", "password": "pwd_3"} + config_3, + { + "host": "host_3", + "dbname": "db_3", + "port": "3333", + "user": "user_3", + "password": "pwd_3", # nosec B105 + }, ) config_2 = service_config("service_2") write_service("service_3", config_2) @@ -127,7 +141,13 @@ def test_write_service(self): ) # add new service - new_srv_settings = {"host": "host_4", "dbname": "db_4", "port": 4444, "user": "user_4", "password": "pwd_4"} + new_srv_settings = { + "host": "host_4", + "dbname": "db_4", + "port": 4444, + "user": "user_4", + "password": "pwd_4", # nosec B105 + } new_srv = write_service(service_name="service_4", settings=new_srv_settings, create_if_not_found=True) self.assertIsInstance(new_srv, dict) self.assertIn("service_4", service_names())