Run bandit when verifying changes 50/67950/1
authorCédric Ollivier <cedric.ollivier@orange.com>
Sat, 25 May 2019 09:10:55 +0000 (11:10 +0200)
committerCédric Ollivier <cedric.ollivier@orange.com>
Sat, 25 May 2019 09:25:37 +0000 (11:25 +0200)
commit01d6c209e81e0b954e58811167285ab264de079c
tree31135be20d5d99d98571720f55016cfac7f4a417
parent0e19012c4f11cc09c323476511893bbf3893a508
Run bandit when verifying changes

It reports only MEDIUM issues or higher like nova [1].
It selects bandit 1.1.0 as defined in nova and neutron lower
constraints [2].

[1] https://github.com/openstack/nova/blob/master/tox.ini#L221
[2] https://github.com/openstack/nova/blob/master/lower-constraints.txt#L8

Change-Id: I6fc505f684701792d3e03659eb0feea8321452c0
Signed-off-by: Cédric Ollivier <cedric.ollivier@orange.com>
(cherry picked from commit 0440ffcac18991395799e5aafc9243e028917ab6)
test-requirements.txt
tox.ini
upper-constraints.txt