From 0e9e22da186483ea05670fc451d56cc78dc53cb2 Mon Sep 17 00:00:00 2001 From: flan Date: Mon, 13 Jul 2026 16:53:08 +0000 Subject: [PATCH] Annotate the two remaining static-analysis findings in alert_source.py subprocess is called in list form with only literal arguments -- nothing user-supplied reaches the command line -- and the partial `git` path is moot in a module that only ever runs as root inside middlewared. Deliberately NOT tagged: this changes no behaviour, and cutting a release for two noqa comments would raise an update alert on every user's box. main sits one commit ahead of v0.5.1 until the next real change -- which is exactly the restraint the alert's docs-only rule exists to encode. --- patch/alert_source.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/patch/alert_source.py b/patch/alert_source.py index 7980c73..56ec4bd 100644 --- a/patch/alert_source.py +++ b/patch/alert_source.py @@ -83,7 +83,11 @@ class TrueCloudPatchUpdateAlertSource(ThreadedAlertSource): # ── internals ──────────────────────────────────────────────────────────── def _git(self, *args): - return subprocess.run( + # List form, never shell=True, and every `args` value is a literal from + # this file -- nothing user-supplied reaches the command line. The partial + # `git` path is moot: this runs as root inside middlewared, so anyone who + # can poison PATH already has root. + return subprocess.run( # noqa: S603, S607 ["git", "-C", PATCH_DIR, *args], capture_output=True, text=True, timeout=_TIMEOUT, check=True, ).stdout