Skip to content

fix(SEC-004): stop shipping pytest in the production image - #122

Merged
DoRmAmMu1997 merged 2 commits into
mainfrom
fix/sec-004-pytest-out-of-prod-image
Sep 24, 2026
Merged

DoRmAmMu1997 merged 2 commits into
mainfrom
fix/sec-004-pytest-out-of-prod-image

Conversation

@DoRmAmMu1997

@DoRmAmMu1997 DoRmAmMu1997 commented Sep 4, 2026 •

Copy link
Copy Markdown
Owner

Closes #121.

The production image installed pytest through the runtime requirements. Keep it in development requirements and enforce both sides of that separation: verification tools must be absent from runtime inputs and present in development inputs.

The guard now compares normalized project names, so versions, extras, environment markers, inline comments, case, and equivalent dot/underscore/hyphen spellings cannot hide a declaration. Regressions exercise the real guard with in-memory requirements text. Google-style helper documentation and Beginner notes explain the failure cases.

Validation:

  • Python 3.11 full suite: 2,045 passed, 1 skipped; 89.73% coverage including app.py.
  • Final policy module: 24 passed on each of Python 3.11 and 3.12.
  • Pre-commit configuration, compileall, Ruff, mypy, Bandit, pip-audit, and diff checks passed.
  • The runtime/development dependency versions are unchanged. Hosted Python 3.11/3.12, Docker and CodeQL checks will validate the pushed head.

The original pytest-removal change is retained. Optional indicator dependency maintenance is tracked separately in the approved modernization plan.

Original PR developed with Claude Code; this follow-up is co-authored by Codex.

`requirements.txt` declared `pytest` as a runtime dependency under a "Test
runner." heading. The Dockerfile installs `requirements.txt` and nothing else,
so the test runner and its dependency tree were baked into the deployed image -
on both the Render web service and the daily-scan cron.

It was already declared in `requirements-dev.txt`, so this was a duplicate that
bought nothing and only widened the production surface.

Remove it, and add a policy guard so it cannot drift back. The guard checks the
whole class of developer tooling (pytest, pytest-cov, ruff, bandit, pip-audit,
mypy, pre-commit) and asserts each one is absent from requirements.txt AND still
present in requirements-dev.txt - so the fix cannot be "solved" by deleting the
dependency outright either. Verified by re-adding pytest to requirements.txt and
watching the guard fail.

The existing `constraints.txt` pin for pytest is untouched and still correct:
constraints only pin versions for whatever is actually being installed, and CI
installs both requirements files.

Closes #121

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
DoRmAmMu1997 added a commit that referenced this pull request Sep 4, 2026
OBS-004 (#119/#124), QUAL-009 (#120/#123) and SEC-004 (#121/#122) were filed and
built immediately after the audit, so the register should not describe them as
untouched. The remaining entries stay as recorded findings.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

@DoRmAmMu1997 DoRmAmMu1997 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review finding: the development-tool guard matches only bare requirement lines, so versioned, commented, marked, and normalized spellings can bypass it (for example pytest==9.1.1 and pytest_cov). The production removal itself is correct. Strengthen name extraction and test both runtime exclusion and development presence, with beginner-friendly explanations.

Evidence: tests/test_supply_chain_policy.py at the reviewed head. This is a policy-test gap, not an existing production vulnerability.

Normalize project names across versions, extras, markers, comments and
equivalent punctuation; exercise both runtime exclusion and development
presence through the real guard. Explain the original failure and the
policy boundary in beginner-friendly docstrings.

Co-authored-by: Codex <codex@openai.com>
@DoRmAmMu1997
DoRmAmMu1997 merged commit e2b9975 into main Sep 24, 2026
6 of 7 checks passed
@DoRmAmMu1997
DoRmAmMu1997 deleted the fix/sec-004-pytest-out-of-prod-image branch September 24, 2026 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SEC-004: stop shipping pytest in the production image

1 participant