From e62b116e0b57aef73882ee4689153eda326c399f Mon Sep 17 00:00:00 2001 From: Peter Corke Date: Sun, 16 Aug 2026 13:32:36 +1000 Subject: [PATCH] fix: exclude tests/ from Bandit's assert_used (B101) check Bare `assert` is idiomatic pytest style (~45 test-suite uses), not a security concern -- B101 exists to catch assert used for real validation in src/ (asserts vanish under `python -O`), where it's still doing legitimate work (48 findings there, unaffected by this change). Verified with a throwaway venv: `bandit -c pyproject.toml -r src tests` now reports the same 48 issues as `-r src` alone (was 93 combined before this config), and `-r src` alone is unchanged. Codacy's Python engine is Prospector, which wraps Bandit and honours this native pyproject.toml config directly -- no Codacy-side setting needed. Co-Authored-By: Claude Sonnet 5 --- pyproject.toml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pyproject.toml b/pyproject.toml index f23e7360..279d73b9 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -119,6 +119,14 @@ select = ["E", "F", "I"] [tool.ruff.lint.isort] known-first-party = ["machinevisiontoolbox"] +[tool.bandit] +# bare `assert` is idiomatic pytest style, not a security concern -- Bandit's +# B101 ("assert used") is meant for src/, where assert can silently vanish +# under `python -O`. Excluding tests/ keeps that check meaningful without +# flagging every test assertion (Codacy runs Bandit via Prospector and +# honours this file). +exclude_dirs = ["tests"] + [tool.pyright] include = ["src"] ignore = ["docs", "tests", "examples"]