Skip to content

test: clear two test-only CodeQL alerts - #184

Open
chrisknvidia wants to merge 1 commit into
mainfrom
fix/christopherk/codeql-test-alerts
Open

chrisknvidia wants to merge 1 commit into
mainfrom
fix/christopherk/codeql-test-alerts

Conversation

@chrisknvidia

Copy link
Copy Markdown
Collaborator

Clears two open CodeQL alerts on main. Both are in tests; no product code changes.

  • py/incomplete-url-substring-sanitization (tests/test_provider_config.py): the no-credential test checked that build.nvidia.com appeared somewhere in the setup message. It now checks the exact Get a key: https://build.nvidia.com line, which is stricter.
  • py/clear-text-storage-sensitive-data (tests/test_harbor_local_sandbox.py): the bwrap host-home test wrote a value named secret to a file in the host home. The test only needs recognizable text to prove the sandbox can't read that file, so it now writes a plain marker. The assertions are unchanged apart from the name.

The three py/redos alerts in validators/security.py and the test_schema.py alert are fixed on PR #28, which edits those files.

Verified: ruff check and both test files pass (204 passed, 5 skipped; the bwrap tests skip on macOS and run on Linux CI).

🤖 Generated with Claude Code

py/incomplete-url-substring-sanitization in test_provider_config.py:
the no-credential test checked that "build.nvidia.com" appeared
somewhere in the setup message. It now checks the exact
"  Get a key: https://build.nvidia.com" line, which is stricter.

py/clear-text-storage-sensitive-data in test_harbor_local_sandbox.py:
the bwrap host-home test wrote a value named `secret` to a file in the
host home. The test only needs recognizable text to prove the sandbox
cannot read that file, so the value is now a plain marker.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant