flake8-bandit
's S4
rules don't apply to stubs
#15207
Labels
accepted
Ready for implementation
help wanted
Contributions especially welcome
rule
Implementing or modifying a lint rule
When enabling the
flake8-bandit (S)
category (with preview mode),S4
rules will trigger on imports in stubs of a project. I believe these will always be false-positives and there's no need no need to warn about importing insecure and vulnerable libraries in stubs. Since those are not runtime files. Nothing gets executed.Ruff: 0.8.4 (rules are currently in preview)
(this report is extracted from #14535 (comment) for ease of tracking and discussion)
The text was updated successfully, but these errors were encountered: