You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix: add bandit to dev dependencies and improve security
Changes:
1. Add bandit[toml]>=1.7.0 to dev dependency group for CI security scans
2. Update fastapi to >=0.118,<0.119 and add starlette>=0.47.2,<0.48
to address security vulnerabilities (GHSA-2jv5-9r88-3w3p)
3. Replace SHA-1 with SHA-256 in file comparison module for better
cryptographic security
Root cause of CI failure:
- Bandit was configured in pyproject.toml but not listed as a dependency
- CI workflow ran 'uv run bandit' causing "No such file or directory" error
Security improvements:
- SHA-256 is more resistant to collision attacks than deprecated SHA-1
- Updated dependencies address known vulnerabilities
- Bandit static analysis now properly configured for CI/CD pipeline
Verified:
✅ uv run bandit --version works (returns 1.8.6)
✅ Bandit scan runs successfully
✅ All 382 tests pass in ~0.4 seconds
✅ Code quality checks pass (ruff format, ruff check, mypy)
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
fix: cicd issue and update code.
Copy file name to clipboardExpand all lines: CLAUDE.md
+32-8Lines changed: 32 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,20 +6,44 @@ This file provides guidance to Claude Code (claude.ai/code) when working with co
6
6
7
7
DLsite Classification Manager is a high-performance DLsite works classification and management tool with a modern web interface and complete API functionality. It automatically extracts and manages metadata for DLsite content (identified by codes: RJ, BJ, VJ, RE, BE, VE).
8
8
9
-
## Running Unit Tests
9
+
## Code Quality Checks
10
10
11
-
**IMPORTANT: Always run tests using the standardized script to ensure consistent results.**
11
+
**CRITICAL: Always run these checks after ANY code changes before committing.**
12
12
13
-
To verify unit tests after any code changes:
13
+
### Required Quality Checks (Run in Order)
14
14
15
+
1.**Format Code** (auto-fixes formatting issues):
16
+
```bash
17
+
uv run ruff format .
18
+
```
19
+
20
+
2.**Lint and Auto-fix** (auto-fixes linting issues):
21
+
```bash
22
+
uv run ruff check --fix .
23
+
```
24
+
25
+
3.**Type Check** (validates type hints):
26
+
```bash
27
+
uv run mypy .
28
+
```
29
+
30
+
4.**Run Tests** (validates functionality):
31
+
```bash
32
+
./run_tests.sh
33
+
```
34
+
35
+
### Quick Quality Check Script
36
+
37
+
Run all checks at once:
15
38
```bash
16
-
./run_tests.sh
39
+
uv run ruff format .&& uv run ruff check --fix .&& uv run mypy .&&./run_tests.sh
17
40
```
18
41
19
-
This script ensures:
20
-
- ✅ Tests are run with correct coverage settings
21
-
- ✅ Only tested modules are measured (100% coverage for URL and security modules)
22
-
- ✅ Consistent results between all developers
42
+
**These checks ensure:**
43
+
- ✅ Consistent code formatting (PEP 8 compliant)
44
+
- ✅ No linting errors or code smells
45
+
- ✅ Type safety and correctness
46
+
- ✅ All tests pass with required coverage
23
47
- ✅ Fast execution (~0.4 seconds for 81 tests)
24
48
25
49
**Note**: If you see "bad interpreter" error on WSL/Linux, the file may have Windows line endings. Fix with:
0 commit comments