Commit 6f61cdc
committed
Wire bandit into make ci, scan tests/ too, update CLAUDE.md
Wanted make ci to be the one command that catches everything locally -- same as what the GitHub Action runs. Two things were missing:
- bandit wasn't in requirements.txt (so the venv didn't have it)
- the GH Action was only scanning bitmath/, skipping tests/
Changes:
- Add bandit to requirements.txt
- Add ci-bandit target, scanning bitmath/ and tests/ with -r -v
- Wire ci-bandit into the ci chain between ci-pylint and ci-unittests
- Update GH Action to pass targets: "bitmath/ tests/"
- Update CLAUDE.md: versioning section (VERSION is the single source of truth), security scan section1 parent 8528794 commit 6f61cdc
4 files changed
Lines changed: 24 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| 26 | + | |
| 27 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
33 | 36 | | |
34 | | - | |
| 37 | + | |
35 | 38 | | |
36 | 39 | | |
37 | 40 | | |
| |||
66 | 69 | | |
67 | 70 | | |
68 | 71 | | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
69 | 80 | | |
70 | 81 | | |
71 | 82 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
216 | 216 | | |
217 | 217 | | |
218 | 218 | | |
219 | | - | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
220 | 227 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
1 | 2 | | |
2 | 3 | | |
3 | 4 | | |
| |||
0 commit comments