c8dac10348
* Start of MCP server and test suite * Add MCP server for interacting with meshtastic devices and testing framework / TUI * Update mcp-server/README.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * fix mcp-server review feedback from thread Agent-Logs-Url: https://github.com/meshtastic/firmware/sessions/91dc128a-ed50-4d07-8bb2-3dc6623a05f7 Co-authored-by: thebentern <9000580+thebentern@users.noreply.github.com> * Enhance StreamAPI and PhoneAPI for improved log record handling and concurrency control * Semgrep fixes * Trunk and semgrep fixes * optimize pio streaming tee file writes Agent-Logs-Url: https://github.com/meshtastic/firmware/sessions/04e26c6b-6a2b-45be-bbeb-79ae4d0be633 Co-authored-by: thebentern <9000580+thebentern@users.noreply.github.com> * chore: remove redundant log handle assignment Agent-Logs-Url: https://github.com/meshtastic/firmware/sessions/04e26c6b-6a2b-45be-bbeb-79ae4d0be633 Co-authored-by: thebentern <9000580+thebentern@users.noreply.github.com> * Consolidate type imports and remove placeholder test files * Add tests for config persistence and more exchange messages * Refactor position test to validate on-demand request/reply behavior * Remove position request/reply test and update README for telemetry behavior * Fix transmit history file to get removed on factory reset --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
28 lines
1.4 KiB
Plaintext
28 lines
1.4 KiB
Plaintext
[bandit]
|
|
# Rule IDs: https://bandit.readthedocs.io/en/latest/plugins/index.html
|
|
#
|
|
# B101 assert_used
|
|
# pytest assertions + internal invariants; required for pytest.
|
|
# B110 try_except_pass
|
|
# best-effort cleanup paths (atexit handlers, pubsub unsubscribe,
|
|
# session-end file close, socket shutdown). Logging inside the
|
|
# except block would be worse than the silent pass — teardown is
|
|
# already at end-of-session and the surrounding caller has context.
|
|
# B112 try_except_continue
|
|
# defensive loops over flaky sources (pubsub handlers, device
|
|
# re-enumeration polls). One failed iteration shouldn't abort the loop.
|
|
# B404 import_subprocess
|
|
# mcp-server wraps PlatformIO, esptool, nrfutil, picotool, and the
|
|
# pytest test-runner — subprocess is a load-bearing import here, not
|
|
# a smell. The "consider possible security implications" advisory is
|
|
# redundant given the file-level review already applied.
|
|
# B603 subprocess_without_shell_equals_true
|
|
# all subprocess calls use a static argv list; `shell=False` is the
|
|
# default and we never string-interpolate user input into the command.
|
|
# B606 start_process_with_no_shell
|
|
# same invariant as B603 — running a binary via argv list (not
|
|
# `shell=True`) is the safe pattern bandit is asking for.
|
|
#
|
|
# Higher-severity checks (B102 exec_used, B301 pickle, B307 eval,
|
|
# B602 shell=True, etc.) remain enabled.
|
|
skips = B101,B110,B112,B404,B603,B606 |