Python poetry alerts
Open
question
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
I've setup basic CodeQL pipeline for python and I'm using poetry as dependency manager.
What I found out is that if file `poerty.toml` with configuration below is present (venv is created in `$PWD/.venv`)
```
[virtualenvs]
in-project = true
```
then the pipeline starts report bunch of alerts regarding urllib, requests, etc.

If I remove `poetry.toml` the alerts are gone (venv is created in `/home/runner/.cache/pypoetry/virtualenvs`)
I'm not sure if I should be getting the alerts or not. However the behavior should be consistent in both cases.
Contributor guide
Assessment
This issue has not been assessed yet.