github / github/codeql

Python poetry alerts

オープン
#9,897 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

I've setup basic CodeQL pipeline for python and I'm using poetry as dependency manager.

What I found out is that if file `poerty.toml` with configuration below is present (venv is created in `$PWD/.venv`)
```
[virtualenvs]
in-project = true
```

then the pipeline starts report bunch of alerts regarding urllib, requests, etc.
![image](https://user-images.githubusercontent.com/22962839/181042606-275e1d3e-b792-4ab7-93f2-9f27dde45fe3.png)

If I remove `poetry.toml` the alerts are gone (venv is created in `/home/runner/.cache/pypoetry/virtualenvs`)

I'm not sure if I should be getting the alerts or not. However the behavior should be consistent in both cases.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。