From 057c86de8cb99ee83fd509d90959c5b0f0d5a276 Mon Sep 17 00:00:00 2001 From: Niels Lohmann Date: Thu, 1 Oct 2026 10:28:47 +0200 Subject: [PATCH] Mark compare.py's subprocess and download calls for Bandit The commands are argument lists the script builds itself, and the downloads are pinned https URLs whose SHA-256 is checked. Signed-off-by: Niels Lohmann --- tests/benchmarks/json_view/compare.py | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/tests/benchmarks/json_view/compare.py b/tests/benchmarks/json_view/compare.py index 0901011ca..91e7d0a83 100755 --- a/tests/benchmarks/json_view/compare.py +++ b/tests/benchmarks/json_view/compare.py @@ -30,7 +30,8 @@ import platform import re import shlex import shutil -import subprocess +# runs only the compilers and benchmark binaries this script builds +import subprocess # nosec B404 import sys import tarfile import urllib.request @@ -71,12 +72,14 @@ DEFAULT_CORPUS = [ def run(cmd, **kwargs): print('+ ' + ' '.join(shlex.quote(c) for c in cmd), flush=True) - return subprocess.run(cmd, check=True, **kwargs) + # cmd is an argument list built by this script, never a shell string + return subprocess.run(cmd, check=True, **kwargs) # nosec B603 def output(cmd): try: - return subprocess.run(cmd, check=True, capture_output=True, text=True).stdout.strip() + # cmd is an argument list built by this script, never a shell string + return subprocess.run(cmd, check=True, capture_output=True, text=True).stdout.strip() # nosec B603 except (OSError, subprocess.CalledProcessError): return '' @@ -150,7 +153,8 @@ def download_library(name, work): os.makedirs(os.path.dirname(archive), exist_ok=True) if not os.path.isfile(archive): print(f'downloading {pin["url"]}', flush=True) - urllib.request.urlretrieve(pin['url'], archive) + # the URLs are the https constants in PINNED, and the SHA-256 is checked below + urllib.request.urlretrieve(pin['url'], archive) # nosec B310 with open(archive, 'rb') as f: digest = hashlib.sha256(f.read()).hexdigest() if digest != pin['sha256']: @@ -160,7 +164,7 @@ def download_library(name, work): with tarfile.open(archive) as t: # (the 'data' filter rejects links and paths outside the target where Python has it) kwargs = {'filter': 'data'} if hasattr(tarfile, 'data_filter') else {} - t.extractall(os.path.join(work, 'download'), **kwargs) # noqa: S202 (checked archive) + t.extractall(os.path.join(work, 'download'), **kwargs) # noqa: S202 (checked archive) # nosec B202 if name == 'yyjson': return Library(name, [os.path.join(src, 'src')], [os.path.join(src, 'src', 'yyjson.c')], [], pin['version']) if name == 'simdjson':