Repository navigation
Conversation
…terize SQL and clean comments - Makefile: add bandit and bandit-strict targets\n- requirements-dev: include bandit\n- backend: parameterize SQL queries, safe dynamic clauses\n- request_utils: enforce default timeouts; add tests for timeouts\n- services: safer shelve usage and logging\n- ai-context: add comments policy and security annotations policy\n- main: configurable uvicorn host/port
Code Review Agent (Python)Analyzed 9 Python file(s). Ruff findings: 0 Bandit findings: 27 ./rdm-review-dashboard-backend/src/services/dataverse/postgresql.py
./rdm-review-dashboard-backend/tests/test_postgresql_params.py
./rdm-review-dashboard-backend/tests/test_request_utils_timeouts.py
Note: This is advisory and does not block the PR. Consider addressing issues above. |
…ect; reduce comment noise
Code Review Agent (Python)Analyzed 9 Python file(s). Ruff findings: 0 Bandit findings: 3 ./rdm-review-dashboard-backend/src/services/dataverse/postgresql.py
Note: This is advisory and does not block the PR. Consider addressing issues above. |
|
/gov |
Governance Agent ReportChanged files (15):
Detected change types:
Missing or incomplete items:
Tip: Use the PR template fields to satisfy these checks. Run /gov help for commands. Also try: /gov links and /gov autofill apply. |
|
/gov copilot |
|
/gov links |
|
/gov autofill apply |
Governance reports summaryRun ID: 17646060218 ScanCode (licenses)
SBOM (SPDX)
|
|
/gov |
Governance Agent ReportChanged files (15):
Detected change types:
Missing or incomplete items:
Tip: Use the PR template fields to satisfy these checks. Run /gov help for commands. Also try: /gov links and /gov autofill apply. |
|
/gov copilot |
|
/gov links |
|
/gov autofill apply |
Governance reports summaryRun ID: 17646060218 ScanCode (licenses)
SBOM (SPDX)
|
…mment; upload artifacts
Code Review Agent (Python)Analyzed 9 Python file(s). Ruff findings: 0 Bandit findings: 3 ./rdm-review-dashboard-backend/src/services/dataverse/postgresql.py
Note: This is advisory and does not block the PR. Consider addressing issues above. |
There was a problem hiding this comment.
Pull Request Overview
This PR adds security hardening measures for the backend, including SQL parameterization, HTTP timeout enforcement, and Bandit static analysis tooling. The changes focus on preventing SQL injection vulnerabilities and ensuring proper timeout handling for all HTTP requests.
- Adds comprehensive test coverage for timeout enforcement in all HTTP request functions
- Parameterizes all PostgreSQL queries to prevent SQL injection attacks
- Integrates Bandit security scanning with both local Make targets and CI workflows
Reviewed Changes
Copilot reviewed 15 out of 15 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| rdm-review-dashboard-backend/tests/test_request_utils_timeouts.py | New test file verifying timeout parameter usage in HTTP request functions |
| rdm-review-dashboard-backend/tests/test_postgresql_params.py | New test file ensuring all PostgreSQL queries use proper parameterization |
| rdm-review-dashboard-backend/src/utils/request_utils.py | Enforces DEFAULT_TIMEOUT=30s for all HTTP requests replacing timeout=None |
| rdm-review-dashboard-backend/src/services/note.py | Adds nosec annotations for trusted shelve usage and improves error handling |
| rdm-review-dashboard-backend/src/services/locks.py | Similar shelve hardening and error handling improvements |
| rdm-review-dashboard-backend/src/services/issue.py | Shelve security annotations and enhanced exception handling |
| rdm-review-dashboard-backend/src/services/email.py | Adds nosec annotation for password variable false positive |
| rdm-review-dashboard-backend/src/services/dataverse/postgresql.py | Comprehensive SQL parameterization replacing string interpolation |
| rdm-review-dashboard-backend/src/main.py | Configurable uvicorn host binding defaulting to localhost for safety |
| rdm-review-dashboard-backend/requirements-dev.txt | Adds bandit dependency for security scanning |
| rdm-review-dashboard-backend/pyproject.toml | Bandit configuration excluding tests and B101 |
| ai-context.md | Documents security annotation policies and comment guidelines |
| Makefile | Adds bandit and bandit-strict targets for local security scanning |
| .github/workflows/code-review-agent.yml | Updates Bandit integration with config file support and output truncation |
| .github/workflows/ai-governance.yml | Adds Bandit scanning to governance workflow |
Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
AI prompts used in this PR session
Timestamp: 2025-09-11T13:28:00Z |
@AI-Tool: Copilot
Summary
AI Provenance (required for AI-assisted changes)
Compliance checklist
Tests & Risk