github / github/codeql

Python poetry alerts

未關閉
#9,897 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

I've setup basic CodeQL pipeline for python and I'm using poetry as dependency manager.

What I found out is that if file `poerty.toml` with configuration below is present (venv is created in `$PWD/.venv`)
```
[virtualenvs]
in-project = true
```

then the pipeline starts report bunch of alerts regarding urllib, requests, etc.
![image](https://user-images.githubusercontent.com/22962839/181042606-275e1d3e-b792-4ab7-93f2-9f27dde45fe3.png)

If I remove `poetry.toml` the alerts are gone (venv is created in `/home/runner/.cache/pypoetry/virtualenvs`)

I'm not sure if I should be getting the alerts or not. However the behavior should be consistent in both cases.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。