From 33bb3b81ba5167873a3674c46eb2537548f21a9c Mon Sep 17 00:00:00 2001 From: "patchback[bot]" <45432694+patchback[bot]@users.noreply.github.com> Date: Tue, 30 Jun 2026 11:48:42 -0400 Subject: [PATCH] ci: suppress SonarCloud python:S5443 for test code (#1165) (#1168) Unit tests pass hardcoded '/tmp/...' strings as fake module arguments (for example chart_ref) into fully mocked helm commands, so no file is ever created and there is no real exposure. SonarCloud's python:S5443 still raises a security hotspot on each literal and, because it only scores new code, drops a PR's security rating even though the same pattern already pervades the existing test suite. Scope the suppression to tests/** only. Production code creates temporary files via tempfile.mkstemp / NamedTemporaryFile and remains covered by the rule, where it carries real value. AI-assisted commit with Claude Opus (cherry picked from commit 0836e96c2d333d3e761ff7e60bb37986ff55342b) Co-authored-by: Yuriy Novostavskiy --- sonar-project.properties | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/sonar-project.properties b/sonar-project.properties index f1246d96..e0127b78 100644 --- a/sonar-project.properties +++ b/sonar-project.properties @@ -17,6 +17,14 @@ sonar.exclusions=tests/**,.tox/** # constructor (not {...} literals) for readability and consistency across the # collection. Suppress python:S7498 ("prefer literal syntax"), which conflicts # with that convention and otherwise re-fires on every new module argument. -sonar.issue.ignore.multicriteria=e1 +sonar.issue.ignore.multicriteria=e1,e2 sonar.issue.ignore.multicriteria.e1.ruleKey=python:S7498 sonar.issue.ignore.multicriteria.e1.resourceKey=**/*.py + +# Unit tests pass hardcoded '/tmp/...' strings as fake module arguments (e.g. +# chart_ref) to fully mocked commands; no file is ever created there. Suppress +# python:S5443 ("temporary files in publicly writable directories") for test +# code only. Production code creates temp files via tempfile.mkstemp / +# NamedTemporaryFile and stays covered by the rule. +sonar.issue.ignore.multicriteria.e2.ruleKey=python:S5443 +sonar.issue.ignore.multicriteria.e2.resourceKey=tests/**/*.py