Configure bandit for 'spoils' usage

i.e. B380: No os.path.join misuse.

See https://github.com/bugsink/spoils

rather than think-carefully-and-explain-with-nosec, just switch to
safe_join: this saves future readers the pain of validating whether
all assumptions are (still) correct at a (small) performance cost.

See #175
This commit is contained in:
Klaas van Schelven
2025-07-30 14:00:39 +02:00
parent 462a3169cd
commit 89db6d2899
2 changed files with 4 additions and 3 deletions

View File

@@ -51,9 +51,9 @@ jobs:
with:
python-version: 3.12
- name: Install Bandit
- name: Install Bandit and Plugins
run: |
pip install bandit
pip install bandit spoils
- name: Run Bandit and format results
shell: bash