Compare commits

..
2 Commits
Author SHA1 Message Date
flan 8a82bde531 noqa placement: ruff anchors S607 to the args list, not the call 2026-07-13 16:53:59 +00:00
flan 0e9e22da18 Annotate the two remaining static-analysis findings in alert_source.py
subprocess is called in list form with only literal arguments -- nothing
user-supplied reaches the command line -- and the partial `git` path is moot in a
module that only ever runs as root inside middlewared.

Deliberately NOT tagged: this changes no behaviour, and cutting a release for two
noqa comments would raise an update alert on every user's box. main sits one commit
ahead of v0.5.1 until the next real change -- which is exactly the restraint the
alert's docs-only rule exists to encode.
2026-07-13 16:53:08 +00:00
+6 -2
View File
@@ -83,8 +83,12 @@ class TrueCloudPatchUpdateAlertSource(ThreadedAlertSource):
# ── internals ────────────────────────────────────────────────────────────
def _git(self, *args):
return subprocess.run(
["git", "-C", PATCH_DIR, *args],
# List form, never shell=True, and every `args` value is a literal from
# this file -- nothing user-supplied reaches the command line. The partial
# `git` path is moot: this runs as root inside middlewared, so anyone who
# can poison PATH already has root.
return subprocess.run( # noqa: S603
["git", "-C", PATCH_DIR, *args], # noqa: S607
capture_output=True, text=True, timeout=_TIMEOUT, check=True,
).stdout