github / github/codeql

Python poetry alerts

Open
#9,897 1 comment 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

I've setup basic CodeQL pipeline for python and I'm using poetry as dependency manager.

What I found out is that if file `poerty.toml` with configuration below is present (venv is created in `$PWD/.venv`)
```
[virtualenvs]
in-project = true
```

then the pipeline starts report bunch of alerts regarding urllib, requests, etc.
![image](https://user-images.githubusercontent.com/22962839/181042606-275e1d3e-b792-4ab7-93f2-9f27dde45fe3.png)

If I remove `poetry.toml` the alerts are gone (venv is created in `/home/runner/.cache/pypoetry/virtualenvs`)

I'm not sure if I should be getting the alerts or not. However the behavior should be consistent in both cases.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.