It reports only MEDIUM issues or higher like nova [1].
It selects bandit 1.1.0 as defined in nova and neutron lower
constraints [2].
[1] https://github.com/openstack/nova/blob/master/tox.ini#L221
[2] https://github.com/openstack/nova/blob/master/lower-constraints.txt#L8
Change-Id: I52524df867d99fae75798475c762a5f8253dacfa
Signed-off-by: Cédric Ollivier <cedric.ollivier@orange.com>
(cherry picked from commit
c659caccbf1f55db4e6e3cb31bf088ac57751e86)
doc8 # Apache-2.0
bashate # Apache-2.0
ansible-lint
+bandit
build.sh
commands = bashate {[testenv:bashate]files}
+[testenv:bandit]
+basepython = python2.7
+commands = bandit -r xtesting -x tests -n 5 -ll -s B602
+
[testenv:cover]
basepython = python2.7
dirs =
robotframework===3.0.2
+bandit===1.1.0