Annotate the two remaining static-analysis findings in alert_source.py

subprocess is called in list form with only literal arguments -- nothing
user-supplied reaches the command line -- and the partial `git` path is moot in a
module that only ever runs as root inside middlewared.

Deliberately NOT tagged: this changes no behaviour, and cutting a release for two
noqa comments would raise an update alert on every user's box. main sits one commit
ahead of v0.5.1 until the next real change -- which is exactly the restraint the
alert's docs-only rule exists to encode.
This commit is contained in:
flan
2026-07-13 16:53:08 +00:00
parent bf6d37e621
commit 0e9e22da18
+5 -1
View File
@@ -83,7 +83,11 @@ class TrueCloudPatchUpdateAlertSource(ThreadedAlertSource):
# ── internals ────────────────────────────────────────────────────────────
def _git(self, *args):
return subprocess.run(
# List form, never shell=True, and every `args` value is a literal from
# this file -- nothing user-supplied reaches the command line. The partial
# `git` path is moot: this runs as root inside middlewared, so anyone who
# can poison PATH already has root.
return subprocess.run( # noqa: S603, S607
["git", "-C", PATCH_DIR, *args],
capture_output=True, text=True, timeout=_TIMEOUT, check=True,
).stdout