Pylint Secure Coding Standard Plugin
pylint plugin that enforces some secure coding standards.
Installation
pip install pylint-secure-coding-standard
Pylint codes
| Code | Description |
|---|---|
| R8000 | Use os.path.realpath() instead of os.path.abspath() and os.path.relpath() |
| E8001 | Avoid using exec() and eval() |
| E8002 | Avoid using os.system() |
| E8003 | Avoid using shell=True in subprocess functions or using functions that internally set this |
| R8004 | Avoid using tempfile.mktemp(), prefer tempfile.mkstemp() instead |
| E8005 | Avoid using unsafe PyYAML loading functions |
| E8006 | Avoid using jsonpickle.decode() |
| C8007 | Avoid debug statement in production code |
| C8008 | Avoid assert statements in production code |
| R8009 | Use of builtin open for writing is discouraged in favor of os.open to allow for setting file permissions |
| E8010 | Avoid using os.popen() as it internally uses subprocess.Popen with shell=True |
| E8011 | Use of shlex.quote() should be avoided on non-POSIX platforms |
| W8012 | Avoid using os.open() with unsafe permissions permissions |
| E8013 | Avoid using pickle.load() and pickle.loads() |
| E8014 | Avoid using marshal.load() and marshal.loads() |
| E8015 | Avoid using shelve.open() |
| W8016 | Avoid using os.mkdir and os.makedirs with unsafe file permissions |
| W8017 | Avoid using os.mkfifo with unsafe file permissions |
| W8018 | Avoid using os.mknod with unsafe file permissions |
| W8019 | Avoid using os.chmod with unsafe permissions (W ^ X for group and others) |
Plugin configuration options
This plugin supports some configuration options that may either be specified directly on the command line with a flag
using the option name as --name or by specifying them in one of pylint's configuration files (ie. pyproject.toml,
pylintrc, etc.).
Available options:
| Option name | Option type | Default value | Related error code |
|---|---|---|---|
| os-open-mode | mode-like | 0 (off) | W8012 |
| os-mkdir-mode | mode-like | 0 (off) | E8016 |
| os-mkfifo-mode | mode-like | 0 (off) | E8017 |
| os-mknod-mode | mode-like | 0 (off) | E8018 |
Mode-like options
Mode-like options are configuration options for errors/warnings that relate to some function that accepts a mode
parameter (or similar) that control some file or directory permissions. For those kind of options, the plugin
understands a variety of values that must be specified as string. They will then be parsed into a list of allowed mode
values:
- Any positive, non-zero (octal or decimal) integer value specifies the maximum value for the mode value
- A comma-separated list of (octal or decimal) integers indicates the list of allowed mode values
- 'y', 'yes', 'true' (case-insensitive) will turn on the warnings using the default value of
0o755 - 'n', 'no', 'false' (case-insensitive) will turn off the warnings
Example of values:
[tool.pylint.plugins]
os-open-mode = '0' # check disabled
os-open-mode = 'no' # check disabled
os-open-mode = '493' # all modes from 0 to 493 (=0o755)
os-open-mode = '0o755' # all modes from 0 to 0o755
os-open-mode = '0o755,' # only 0o755 (notice the comma)
os-open-mode = '0o644,0o755' # only 0o644 and 0o755
You can also specify those options directly on the command line:
python3 -m pylint --load-plugins=pylint_secure_coding_standard --os-open-mode='0o755'
Pre-commit hook
See pre-commit for instructions
Sample .pre-commit-config.yaml:
- repo: https://github.com/PyCQA/pylint/
rev: pylint-2.6.0
hooks:
- id: pylint
args: [--load-plugins=pylint_secure_coding_standard]
additional_dependencies: ['pylint-secure-coding-standard']
Metadata
Release files for pylint-secure-coding-standard 1.5.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pylint-secure-coding-standard-1.5.1.tar.gz | 29.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pylint_secure_coding_standard-1.5.1-py2.py3-none-any.whl | Python 3, Python 2 | none | any | Details |
Total release size: 43.0 kB
Release files / pylint-secure-coding-standard-1.5.1.tar.gz
| Download URL | pylint-secure-coding-standard-1.5.1.tar.gz |
|---|---|
| Size | 29.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5e54728165aa773a2e16ae13493d644258f7ecf9f894fafc81b9d5ef4b13e55a
|
|
BLAKE2b-256 checksum How to use checksums |
9cf2f1f4d6dc54d17fac42b8d84c24ba0ccb528fde151501598c1aca197e25a0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.7
|
Release files / pylint_secure_coding_standard-1.5.1-py2.py3-none-any.whl
| Download URL | pylint_secure_coding_standard-1.5.1-py2.py3-none-any.whl |
|---|---|
| Size | 13.6 kB |
| Tags | Python 2 Python 3 |
|
SHA-256 checksum How to use checksums |
5dd75fe1e07b582b0e9ffa3d80f8480f2e6e948caa180f9c09dc9f1a47c366bf
|
|
BLAKE2b-256 checksum How to use checksums |
6525664ff17532954523604796fa7f17e38c0523fdbe4f45f1a1a9becfc3a253
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.7
|