Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update bandit.yml with version bump #2497

Open
wants to merge 3 commits into
base: main
Choose a base branch
from
Open
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 9 additions & 8 deletions code-scanning/bandit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
# This action will run Bandit on your codebase.
# The results of the scan will be found under the Security tab of your repository.

# https://github.com/marketplace/actions/bandit-scan is ISC licensed, by abirismyname
# https://github.com/marketplace/actions/python-bandit-scan is ISC licensed, by abirismyname and maintained by reactive-firewall
# https://pypi.org/project/bandit/ is Apache v2.0 licensed, by PyCQA

name: Bandit
Expand All @@ -20,29 +20,30 @@ on:
schedule:
- cron: $cron-weekly

permissions: {} # Default global permissions to none.

jobs:
bandit:
permissions:
contents: read # for actions/checkout to fetch code
security-events: write # for github/codeql-action/upload-sarif to upload SARIF results
actions: read # only required for a private repository by github/codeql-action/upload-sarif to get the Action run status

runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v4
reactive-firewall marked this conversation as resolved.
Show resolved Hide resolved
- name: Bandit Scan
uses: shundor/python-bandit-scan@9cc5aa4a006482b8a7f91134412df6772dbda22c
uses: reactive-firewall/python-bandit-scan@ c8b1d56a3964de4e00e7a820dddb38661a4b7566 # v2.1 - c8b1d56a3964de4e00e7a820dddb38661a4b7566
reactive-firewall marked this conversation as resolved.
Show resolved Hide resolved
with: # optional arguments
# exit with 0, even with results found
# exit with 0, even with results found - remove or set to false to fail on results when found.
reactive-firewall marked this conversation as resolved.
Show resolved Hide resolved
exit_zero: true # optional, default is DEFAULT
# Github token of the repository (automatically created by Github)
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Needed to get PR information.
# File or directory to run bandit on
# path: # optional, default is .
# path: "." # optional, default is .
reactive-firewall marked this conversation as resolved.
Show resolved Hide resolved
# Report only issues of a given severity level or higher. Can be LOW, MEDIUM or HIGH. Default is UNDEFINED (everything)
# level: # optional, default is UNDEFINED
# level: high # optional, default is UNDEFINED
reactive-firewall marked this conversation as resolved.
Show resolved Hide resolved
# Report only issues of a given confidence level or higher. Can be LOW, MEDIUM or HIGH. Default is UNDEFINED (everything)
# confidence: # optional, default is UNDEFINED
# confidence: high # optional, default is UNDEFINED
reactive-firewall marked this conversation as resolved.
Show resolved Hide resolved
# comma-separated list of paths (glob patterns supported) to exclude from scan (note that these are in addition to the excluded paths provided in the config file) (default: .svn,CVS,.bzr,.hg,.git,__pycache__,.tox,.eggs,*.egg)
# excluded_paths: # optional, default is DEFAULT
# comma-separated list of test IDs to skip
Expand Down