Skip to content

fix(security): annotate fixed-prefix maturin urlopen for Bandit B310 - #2501

Open
seonghobae wants to merge 1 commit into
mainfrom
fix/bandit-b310-maturin-release-asset
Open

seonghobae wants to merge 1 commit into
mainfrom
fix/bandit-b310-maturin-release-asset

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Why

ab2e9db12 (#2347 line) added urlopen in scripts/ci/verify_release_maturin_tool_assets.py:36 without a B310 annotation. The pinned Bandit gate (--severity-level medium --confidence-level medium) therefore fails on current main and on every PR that runs Python Security (e.g. #2253).

Change

One inline # nosec B310 plus a one-line reason, the same pattern used in materialize_base_python_requirements.py, noema_review_gate.py and sandboxed_web_e2e.py. The URL is a fixed https://github.com/PyO3/maturin/releases/download/v1.15.0/ prefix and verify_assets allowlists asset_filename (line 72) before calling fetch, so no file: or custom scheme is reachable.

Evidence

  • Pinned requirements-bandit-ci-hashes.txt Bandit, the exact workflow command, on origin/main 3295c25: rc=1, scripts/ci/verify_release_maturin_tool_assets.py:36 B310 MEDIUM.
  • Same command on this head: rc=0.
  • pytest tests/test_verify_release_maturin_tool_assets.py: 7 passed.

Developer experience: Python Security goes green again for unrelated PRs.
User experience: no behavior change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WDHB12uwrJ5Uzm8gNSz52N

ab2e9db added an unannotated urlopen in verify_release_maturin_tool_assets.py.
The pinned Bandit gate (MEDIUM/MEDIUM) now fails on main and on every PR.
The URL is a fixed https://github.com prefix and the filename is allowlisted
before fetch, so mark it the same way as the other audited urlopen sites.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WDHB12uwrJ5Uzm8gNSz52N
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 258b1f8c-a230-469d-b01b-37aced112f6b

📥 Commits

Reviewing files that changed from the base of the PR and between 3295c25 and 8db72d9.

📒 Files selected for processing (1)
  • scripts/ci/verify_release_maturin_tool_assets.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

url = f"https://github.com/PyO3/maturin/releases/download/v1.15.0/{filename}"
with urlopen(Request(url, headers={"User-Agent": "cwl-release-gate"}), timeout=60) as response:
# URL is a fixed https://github.com prefix; only the vetted asset filename varies.
with urlopen(Request(url, headers={"User-Agent": "cwl-release-gate"}), timeout=60) as response: # nosec B310

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants