Commit c84aca0
committed
fix: Resolve CI build and security scan issues
- Fix build dependency installation verification in build job
- Fix bandit B324: Use usedforsecurity=False for MD5 cache keys
- Fix bandit B608: Add nosec comments for parameterized SQL queries
- Make bandit fail on high/medium severity issues (remove || true)
- Bandit already runs on all branches, now properly enforced
These SQL queries use parameterized placeholders (?) and are safe
from SQL injection. MD5 is only used for cache key generation, not
cryptographic security.1 parent 131500c commit c84aca0
File tree
4 files changed
+7
-3
lines changed- .github/workflows
- src/aletheia_probe
- backends
4 files changed
+7
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
113 | 113 | | |
114 | 114 | | |
115 | 115 | | |
116 | | - | |
| 116 | + | |
| 117 | + | |
117 | 118 | | |
118 | 119 | | |
119 | 120 | | |
| |||
143 | 144 | | |
144 | 145 | | |
145 | 146 | | |
146 | | - | |
| 147 | + | |
| 148 | + | |
147 | 149 | | |
148 | 150 | | |
149 | 151 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
269 | 269 | | |
270 | 270 | | |
271 | 271 | | |
272 | | - | |
| 272 | + | |
273 | 273 | | |
274 | 274 | | |
275 | 275 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
464 | 464 | | |
465 | 465 | | |
466 | 466 | | |
| 467 | + | |
467 | 468 | | |
468 | 469 | | |
469 | 470 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
182 | 182 | | |
183 | 183 | | |
184 | 184 | | |
| 185 | + | |
185 | 186 | | |
186 | 187 | | |
187 | 188 | | |
| |||
0 commit comments