Skip to content

chore(dev): add bandit target, SQL param hardening, and timeout tests - #4

Closed
ErykKul wants to merge 3 commits into
mainfrom
chore/add-bandit-target-and-minimize-comments
Closed

ErykKul wants to merge 3 commits into
mainfrom
chore/add-bandit-target-and-minimize-comments

Conversation

@ErykKul

@ErykKul ErykKul commented Sep 11, 2025 •

Copy link
Copy Markdown
Contributor

@AI-Tool: Copilot

Summary

  • Add Bandit make targets (non-strict/strict).
  • Parameterize PostgreSQL queries; constant-only clause snippets.
  • Enforce DEFAULT_TIMEOUT=30s for httpx/requests; add tests.
  • Clarify trusted shelve usage; tighten error handling.
  • Safe uvicorn defaults (127.0.0.1:8000); add policies in ai-context.

AI Provenance (required for AI-assisted changes)

  • Prompt: Harden backend (SQL/HTTP), add Bandit targets, minimize inline comments, add tests, open PR.
  • Model: GitHub Copilot
  • Date: 2025-09-11T13:15:00Z
  • Author: GitHub Copilot
  • Role: deployer

Compliance checklist

  • No secrets/PII
  • Agent logging enabled (actions/decisions logged)
  • Kill-switch / feature flag present for AI features
  • No prohibited practices under EU AI Act
  • OWASP ASVS review
  • Risk classification: limited
  • Personal data: no
  • DPIA: N/A
  • Automated decision-making: no
  • Agent mode used: no
  • Role: deployer
  • Vendor GPAI compliance reviewed: N/A
  • License/IP attestation
  • Attribution: N/A
  • Log retention policy: N/A

Tests & Risk

  • Unit/integration tests added/updated
  • Security scan passed
  • Rollback plan: Revert PR; disable new Make targets if needed
  • Smoke test: N/A (non-user-facing tooling and backend hardening)

…terize SQL and clean comments

- Makefile: add bandit and bandit-strict targets\n- requirements-dev: include bandit\n- backend: parameterize SQL queries, safe dynamic clauses\n- request_utils: enforce default timeouts; add tests for timeouts\n- services: safer shelve usage and logging\n- ai-context: add comments policy and security annotations policy\n- main: configurable uvicorn host/port
@github-actions

Copy link
Copy Markdown

Code Review Agent (Python)

Analyzed 9 Python file(s).

Ruff findings: 0

Bandit findings: 27

./rdm-review-dashboard-backend/src/services/dataverse/postgresql.py

  • L164 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.
  • L219 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.
  • L247 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.

./rdm-review-dashboard-backend/tests/test_postgresql_params.py

  • L13 [MEDIUM/MEDIUM] Probable insecure usage of temp file/directory.
  • L36 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L37 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L49 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L50 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L51 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L63 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L64 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L76 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L77 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L89 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L90 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L99 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L101 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L102 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L114 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L115 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.

./rdm-review-dashboard-backend/tests/test_request_utils_timeouts.py

  • L17 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L19 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L26 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L38 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L39 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L46 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
  • L53 [LOW/HIGH] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.

Note: This is advisory and does not block the PR. Consider addressing issues above.

@github-actions

Copy link
Copy Markdown

Code Review Agent (Python)

Analyzed 9 Python file(s).

Ruff findings: 0

Bandit findings: 3

./rdm-review-dashboard-backend/src/services/dataverse/postgresql.py

  • L164 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.
  • L219 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.
  • L247 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.

Note: This is advisory and does not block the PR. Consider addressing issues above.

@ErykKul

ErykKul commented Sep 11, 2025

Copy link
Copy Markdown
Contributor Author

/gov

@github-actions

Copy link
Copy Markdown

Governance Agent Report

PR: #4 by @ErykKul

Changed files (15):

  • .github/workflows/ai-governance.yml
  • .github/workflows/code-review-agent.yml
  • Makefile
  • ai-context.md
  • rdm-review-dashboard-backend/pyproject.toml
  • rdm-review-dashboard-backend/requirements-dev.txt
  • rdm-review-dashboard-backend/src/main.py
  • rdm-review-dashboard-backend/src/services/dataverse/postgresql.py
  • rdm-review-dashboard-backend/src/services/email.py
  • rdm-review-dashboard-backend/src/services/issue.py
  • rdm-review-dashboard-backend/src/services/locks.py
  • rdm-review-dashboard-backend/src/services/note.py
  • rdm-review-dashboard-backend/src/utils/request_utils.py
  • rdm-review-dashboard-backend/tests/test_postgresql_params.py
  • rdm-review-dashboard-backend/tests/test_request_utils_timeouts.py

Detected change types:

  • backend

Missing or incomplete items:

  • None (looks good)

Tip: Use the PR template fields to satisfy these checks.

Run /gov help for commands. Also try: /gov links and /gov autofill apply.

@github-actions

Copy link
Copy Markdown

/gov copilot

@github-actions

Copy link
Copy Markdown

/gov links

@github-actions

Copy link
Copy Markdown

/gov autofill apply

@github-actions

Copy link
Copy Markdown

Governance reports summary

Run ID: 17646060218

ScanCode (licenses)

  • Artifact not found.

SBOM (SPDX)

  • Packages: 48
  • Copyleft package licenses (AGPL/GPL/LGPL): 0
  • Unknown/NoAssertion package licenses: 48

@ErykKul

ErykKul commented Sep 11, 2025

Copy link
Copy Markdown
Contributor Author

/gov

@github-actions

Copy link
Copy Markdown

Governance Agent Report

PR: #4 by @ErykKul

Changed files (15):

  • .github/workflows/ai-governance.yml
  • .github/workflows/code-review-agent.yml
  • Makefile
  • ai-context.md
  • rdm-review-dashboard-backend/pyproject.toml
  • rdm-review-dashboard-backend/requirements-dev.txt
  • rdm-review-dashboard-backend/src/main.py
  • rdm-review-dashboard-backend/src/services/dataverse/postgresql.py
  • rdm-review-dashboard-backend/src/services/email.py
  • rdm-review-dashboard-backend/src/services/issue.py
  • rdm-review-dashboard-backend/src/services/locks.py
  • rdm-review-dashboard-backend/src/services/note.py
  • rdm-review-dashboard-backend/src/utils/request_utils.py
  • rdm-review-dashboard-backend/tests/test_postgresql_params.py
  • rdm-review-dashboard-backend/tests/test_request_utils_timeouts.py

Detected change types:

  • backend

Missing or incomplete items:

  • None (looks good)

Tip: Use the PR template fields to satisfy these checks.

Run /gov help for commands. Also try: /gov links and /gov autofill apply.

@github-actions

Copy link
Copy Markdown

/gov copilot

@github-actions

Copy link
Copy Markdown

/gov links

@github-actions

Copy link
Copy Markdown

/gov autofill apply

@github-actions

Copy link
Copy Markdown

Governance reports summary

Run ID: 17646060218

ScanCode (licenses)

  • Copyleft findings (AGPL/GPL/LGPL): 0
  • Unknown/NoAssertion licenses: 0
  • Top files with copyleft/unknown:

SBOM (SPDX)

  • Packages: 48
  • Copyleft package licenses (AGPL/GPL/LGPL): 0
  • Unknown/NoAssertion package licenses: 48

@github-actions

Copy link
Copy Markdown

Code Review Agent (Python)

Analyzed 9 Python file(s).

Ruff findings: 0

Bandit findings: 3

./rdm-review-dashboard-backend/src/services/dataverse/postgresql.py

  • L164 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.
  • L219 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.
  • L247 [MEDIUM/LOW] Possible SQL injection vector through string-based query construction.

Note: This is advisory and does not block the PR. Consider addressing issues above.

@ErykKul
ErykKul requested a review from Copilot September 11, 2025 13:35

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds security hardening measures for the backend, including SQL parameterization, HTTP timeout enforcement, and Bandit static analysis tooling. The changes focus on preventing SQL injection vulnerabilities and ensuring proper timeout handling for all HTTP requests.

  • Adds comprehensive test coverage for timeout enforcement in all HTTP request functions
  • Parameterizes all PostgreSQL queries to prevent SQL injection attacks
  • Integrates Bandit security scanning with both local Make targets and CI workflows

Reviewed Changes

Copilot reviewed 15 out of 15 changed files in this pull request and generated no comments.

Show a summary per file
File Description
rdm-review-dashboard-backend/tests/test_request_utils_timeouts.py New test file verifying timeout parameter usage in HTTP request functions
rdm-review-dashboard-backend/tests/test_postgresql_params.py New test file ensuring all PostgreSQL queries use proper parameterization
rdm-review-dashboard-backend/src/utils/request_utils.py Enforces DEFAULT_TIMEOUT=30s for all HTTP requests replacing timeout=None
rdm-review-dashboard-backend/src/services/note.py Adds nosec annotations for trusted shelve usage and improves error handling
rdm-review-dashboard-backend/src/services/locks.py Similar shelve hardening and error handling improvements
rdm-review-dashboard-backend/src/services/issue.py Shelve security annotations and enhanced exception handling
rdm-review-dashboard-backend/src/services/email.py Adds nosec annotation for password variable false positive
rdm-review-dashboard-backend/src/services/dataverse/postgresql.py Comprehensive SQL parameterization replacing string interpolation
rdm-review-dashboard-backend/src/main.py Configurable uvicorn host binding defaulting to localhost for safety
rdm-review-dashboard-backend/requirements-dev.txt Adds bandit dependency for security scanning
rdm-review-dashboard-backend/pyproject.toml Bandit configuration excluding tests and B101
ai-context.md Documents security annotation policies and comment guidelines
Makefile Adds bandit and bandit-strict targets for local security scanning
.github/workflows/code-review-agent.yml Updates Bandit integration with config file support and output truncation
.github/workflows/ai-governance.yml Adds Bandit scanning to governance workflow

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@ErykKul

ErykKul commented Sep 11, 2025

Copy link
Copy Markdown
Contributor Author

AI prompts used in this PR session

  • Provenance Prompt: Harden backend (SQL/HTTP), add Bandit targets, minimize inline comments, add tests, open PR.
  • Add Makefile target(s) for Bandit and wire dev dependency.
  • Remove inline security comments; add policies to ai-context.md.
  • Add a code guide rule to avoid comments in general; prefer self-documenting code.
  • Create a draft PR using the template; avoid personal emails.
  • Fill out the PR template; include AI Provenance fields.
  • Fix governance error: Missing Prompt/Model/Date/Author by setting literal values.
  • Redo the PR body to be concise, follow the template, and pass governance checks.
  • Align GitHub Actions (Bandit) to ignore tests like local and reduce long review comments.
  • Document all prompts used by commenting to the PR (this comment).

Timestamp: 2025-09-11T13:28:00Z

@ErykKul
ErykKul requested a review from okaradeniz September 11, 2025 13:38
@okaradeniz
okaradeniz marked this pull request as ready for review September 11, 2025 13:40
@ErykKul ErykKul closed this Feb 9, 2026
@ErykKul
ErykKul deleted the chore/add-bandit-target-and-minimize-comments branch February 9, 2026 10:15
@okaradeniz
okaradeniz restored the chore/add-bandit-target-and-minimize-comments branch February 9, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants