ci: suppress SonarCloud python:S5443 for test code (#1165) (#1168)

Unit tests pass hardcoded '/tmp/...' strings as fake module arguments (for
example chart_ref) into fully mocked helm commands, so no file is ever
created and there is no real exposure. SonarCloud's python:S5443 still
raises a security hotspot on each literal and, because it only scores new
code, drops a PR's security rating even though the same pattern already
pervades the existing test suite.

Scope the suppression to tests/** only. Production code creates temporary
files via tempfile.mkstemp / NamedTemporaryFile and remains covered by the
rule, where it carries real value.

AI-assisted commit with Claude Opus

(cherry picked from commit 0836e96c2d)

Co-authored-by: Yuriy Novostavskiy <yuriy@novostavskiy.kyiv.ua>
This commit is contained in:
patchback[bot]
2026-06-30 11:48:42 -04:00
committed by GitHub
parent e4b748a791
commit 33bb3b81ba

View File

@@ -17,6 +17,14 @@ sonar.exclusions=tests/**,.tox/**
# constructor (not {...} literals) for readability and consistency across the
# collection. Suppress python:S7498 ("prefer literal syntax"), which conflicts
# with that convention and otherwise re-fires on every new module argument.
sonar.issue.ignore.multicriteria=e1
sonar.issue.ignore.multicriteria=e1,e2
sonar.issue.ignore.multicriteria.e1.ruleKey=python:S7498
sonar.issue.ignore.multicriteria.e1.resourceKey=**/*.py
# Unit tests pass hardcoded '/tmp/...' strings as fake module arguments (e.g.
# chart_ref) to fully mocked commands; no file is ever created there. Suppress
# python:S5443 ("temporary files in publicly writable directories") for test
# code only. Production code creates temp files via tempfile.mkstemp /
# NamedTemporaryFile and stays covered by the rule.
sonar.issue.ignore.multicriteria.e2.ruleKey=python:S5443
sonar.issue.ignore.multicriteria.e2.resourceKey=tests/**/*.py