Skip to content

fix(find-injection): less noise (shell=True arg lists, bare SQL(), CSP in tests) - #58

Merged
aersam merged 3 commits into
mainfrom
find-injection-noise
Sep 30, 2026
Merged

aersam merged 3 commits into
mainfrom
find-injection-noise

Conversation

@aersam

@aersam aersam commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • subprocess.*([...], shell=True) with a list/tuple whose program (first item) is a literal is no longer reported; later items are arguments, not shell code. A non-literal program or a string command is still an error.
  • A bare SQL(...)/Identifier(...)/Composed(...) (from psycopg.sql import SQL) is trusted like sql.SQL(...).
  • csp-weakened is no longer reported for test files, like every other rule.
  • f-strings stay flagged: t-strings/psycopg.sql are always an option.
  • Python sinks (eval/exec, shell, markup, template) treat a name as constant when every assignment in scope is a constant string (concatenation, f-string of constants, a if c else b, loop over a literal tuple all count). Parameters, +=, any non-constant rebinding, global rebinding and class-body names defeat it.
  • Version 0.28.0.

Test plan

  • pytest (753), ruff, ty
  • new tests for arg lists, bare SQL, and test-file CSP

🤖 Generated with Claude Code

aersam and others added 3 commits September 29, 2026 20:07
…-weakened in tests; bump to 0.28.0

Co-Authored-By: Claude Code <noreply@anthropic.com>
… in Python sinks

Co-Authored-By: Claude Code <noreply@anthropic.com>
…ame:i} identifier)

Co-Authored-By: Claude Code <noreply@anthropic.com>
@aersam
aersam merged commit 9c73285 into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant