Files
analyzeOSDs/.gitea/workflows/security.yml
T
jared fc5ced6315
Lint / Python (flake8) (push) Successful in 2m11s
Security / Python Security (bandit) (push) Successful in 1m13s
Fix CI: install flake8/bandit with --break-system-packages; make scripts lint-clean
The previous attempt used a sed pattern with the wrong indentation and changed nothing. Both
workflows now pass the flag (verified in the diff). render_terminal.py is reformatted to satisfy flake8.
2026-10-03 16:58:52 -04:00

27 lines
595 B
YAML

name: Security
on:
push:
branches: ["**"]
pull_request:
branches: ["**"]
schedule:
- cron: '0 6 * * 1'
jobs:
bandit:
name: Python Security (bandit)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Install bandit
run: |
apt-get update -qq
apt-get install -y -qq python3 python3-pip
# Debian's Python is externally managed (PEP 668); the runner is ephemeral.
pip3 install --break-system-packages bandit
- name: Run bandit
run: bandit -r . --exclude .git,__pycache__ -ll