Commit b1cab54
fix(security): move nosemgrep to same line as subprocess call
Semgrep requires the suppression comment to be on the exact line of the
finding. Preceding-line comments are not reliably associated with the
call when both the finding and suppression are new (introduced in this PR).
Moved all five nosemgrep suppressions to inline on the subprocess.run()
/ Popen() line itself, using the full rule ID:
python.lang.security.audit.dangerous-subprocess-use-audit.dangerous-subprocess-use-audit
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>1 parent e00b731 commit b1cab54
4 files changed
Lines changed: 5 additions & 15 deletions
File tree
- scripts/aidlc-evaluator
- packages/cli-harness/src/cli_harness/adapters
- scripts
Lines changed: 1 addition & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
299 | 299 | | |
300 | 300 | | |
301 | 301 | | |
302 | | - | |
303 | | - | |
304 | | - | |
| 302 | + | |
305 | 303 | | |
306 | 304 | | |
307 | 305 | | |
| |||
Lines changed: 1 addition & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
171 | 171 | | |
172 | 172 | | |
173 | 173 | | |
174 | | - | |
175 | | - | |
176 | | - | |
| 174 | + | |
177 | 175 | | |
178 | 176 | | |
179 | 177 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
96 | | - | |
97 | | - | |
98 | | - | |
| 96 | + | |
99 | 97 | | |
100 | 98 | | |
101 | 99 | | |
| |||
104 | 102 | | |
105 | 103 | | |
106 | 104 | | |
107 | | - | |
108 | | - | |
109 | | - | |
| 105 | + | |
110 | 106 | | |
111 | 107 | | |
112 | 108 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
367 | 367 | | |
368 | 368 | | |
369 | 369 | | |
370 | | - | |
371 | | - | |
372 | | - | |
| 370 | + | |
373 | 371 | | |
374 | 372 | | |
375 | 373 | | |
| |||
0 commit comments