Run bandit when verifying changes 51/67951/1
authorCédric Ollivier <cedric.ollivier@orange.com>
Sat, 25 May 2019 09:10:55 +0000 (11:10 +0200)
committerCédric Ollivier <cedric.ollivier@orange.com>
Sat, 25 May 2019 09:27:13 +0000 (11:27 +0200)
commita58d60b1a0ecab56c140ab5a1b074d5d18ad8051
treef4b5564adee31bcc7b426a9f299b24c52d9b9ba0
parent94b00b4a8fe8f338d2ad60a7c9836013154bb704
Run bandit when verifying changes

It reports only MEDIUM issues or higher like nova [1].
It selects bandit 1.1.0 as defined in nova and neutron lower
constraints [2].

[1] https://github.com/openstack/nova/blob/master/tox.ini#L221
[2] https://github.com/openstack/nova/blob/master/lower-constraints.txt#L8

Change-Id: I6fc505f684701792d3e03659eb0feea8321452c0
Signed-off-by: Cédric Ollivier <cedric.ollivier@orange.com>
(cherry picked from commit 0440ffcac18991395799e5aafc9243e028917ab6)
test-requirements.txt
tox.ini
upper-constraints.txt