Skip to content

Import bandit ruleset from sast rules

Craig Smith requested to merge craigmsmith-swtich-bandit-to-sast-rules into main

What does this MR do?

  • Remove the local bandit ruleset
  • Import bandit ruleset from sast-rules

Note: Changes in the expected JSON are due to two factors:

  • semgrep version update that happened in !276 (merged)
  • Changes in the order of the vulnerability findings

What are the relevant issue numbers?

gitlab-org/gitlab#390908 (closed)

Does this MR meet the acceptance criteria?

Edited by Craig Smith

Merge request reports