From c659caccbf1f55db4e6e3cb31bf088ac57751e86 Mon Sep 17 00:00:00 2001 From: Cédric Ollivier Date: Sat, 25 May 2019 11:03:40 +0200 Subject: Run bandit when verifying changes MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit It reports only MEDIUM issues or higher like nova [1]. It selects bandit 1.1.0 as defined in nova and neutron lower constraints [2]. [1] https://github.com/openstack/nova/blob/master/tox.ini#L221 [2] https://github.com/openstack/nova/blob/master/lower-constraints.txt#L8 Change-Id: I52524df867d99fae75798475c762a5f8253dacfa Signed-off-by: Cédric Ollivier --- upper-constraints.txt | 1 + 1 file changed, 1 insertion(+) (limited to 'upper-constraints.txt') diff --git a/upper-constraints.txt b/upper-constraints.txt index 2ef26717..8b12ecc6 100644 --- a/upper-constraints.txt +++ b/upper-constraints.txt @@ -1 +1,2 @@ robotframework===3.1.1 +bandit===1.1.0 -- cgit 1.2.3-korg