Run bandit when verifying changes 48/67948/3
authorCédric Ollivier <cedric.ollivier@orange.com>
Sat, 25 May 2019 09:03:40 +0000 (11:03 +0200)
committerCédric Ollivier <cedric.ollivier@orange.com>
Sat, 25 May 2019 09:31:20 +0000 (11:31 +0200)
commit21ddea2d58dcc8a6b2e86f63159a42c63d54823d
tree14149cdb7d010cc809e96342725ded45a0ddb8b4
parent8fe65cba9f9f6038e0a4cc95a626a056969685dc
Run bandit when verifying changes

It reports only MEDIUM issues or higher like nova [1].
It selects bandit 1.1.0 as defined in nova and neutron lower
constraints [2].

[1] https://github.com/openstack/nova/blob/master/tox.ini#L221
[2] https://github.com/openstack/nova/blob/master/lower-constraints.txt#L8

Change-Id: I52524df867d99fae75798475c762a5f8253dacfa
Signed-off-by: Cédric Ollivier <cedric.ollivier@orange.com>
(cherry picked from commit c659caccbf1f55db4e6e3cb31bf088ac57751e86)
test-requirements.txt
tox.ini
upper-constraints.txt