From 49bd2dbfe32e4b0a7c166c7bed8daf181346f6b1 Mon Sep 17 00:00:00 2001 From: Tonye Jack Date: Mon, 5 Jul 2021 16:59:36 -0400 Subject: [PATCH 1/4] Update README.md --- README.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/README.md b/README.md index cfcf786..aff484d 100644 --- a/README.md +++ b/README.md @@ -30,7 +30,6 @@ - name: Run bandit uses: tj-actions/bandit@v4.1 with: - version: "1.7.0" targets: | # or a single string "." test_package options: "-r" @@ -40,7 +39,6 @@ | Input | type | required | default | description | |:-------------:|:-----------:|:-------------:|:----------------------------:|:-------------:| -| version | `string` | `true` | `1.7.0` | Bandit version to be installed ([possible choices](https://github.com/PyCQA/bandit/tags)) | | targets | `string[] or string` | `true` | `.` | Targets to run bandit checks | | options | `string` | `true` | `-r` | Extra options ([possible choices](https://github.com/tj-actions/bandit/blob/main/action.yml#L13)) | From 177daf55580e6ce8df7645dfdcfe367f16d88953 Mon Sep 17 00:00:00 2001 From: Tonye Jack Date: Mon, 5 Jul 2021 17:00:24 -0400 Subject: [PATCH 2/4] Update action.yml --- action.yml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/action.yml b/action.yml index ed9cf24..f62682a 100644 --- a/action.yml +++ b/action.yml @@ -2,10 +2,6 @@ name: Run bandit description: A security linter from PyCQA author: tj-actions inputs: - version: - description: bandit version to be used - required: true - default: '1.7.0' targets: description: Module(s)/Package(s) to run bandit checks required: true From c0ee5d6f5213503938e5dc0f9b0687d353d135f1 Mon Sep 17 00:00:00 2001 From: Tonye Jack Date: Mon, 5 Jul 2021 17:00:50 -0400 Subject: [PATCH 3/4] Update entrypoint.sh --- entrypoint.sh | 2 -- 1 file changed, 2 deletions(-) diff --git a/entrypoint.sh b/entrypoint.sh index d637bb9..37b0ca4 100755 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -2,7 +2,5 @@ set -e -pip3 install bandit=="${INPUT_VERSION}". --no-cache-dir - # shellcheck disable=SC2086 bandit ${INPUT_OPTIONS} ${INPUT_TARGETS} From 6dddfda1dc69dc9879444725fdad1b0d1f1b2272 Mon Sep 17 00:00:00 2001 From: Tonye Jack Date: Mon, 5 Jul 2021 17:04:40 -0400 Subject: [PATCH 4/4] Update Dockerfile --- Dockerfile | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/Dockerfile b/Dockerfile index 7697154..a3bd700 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,6 +2,11 @@ FROM python:3.9-slim-buster LABEL maintainer="Tonye Jack " +RUN python3 -m venv /venv && \ + /venv/bin/pip3 install bandit + +ENV PATH="/venv/bin:${PATH}" + COPY entrypoint.sh /entrypoint.sh RUN chmod +x /entrypoint.sh ENTRYPOINT ["/entrypoint.sh"]