Skip to content

Clear the static-analysis findings on the dev-to-main PR - #138

Merged
JE-Chen merged 1 commit into
devfrom
ci-fixes-137
Sep 25, 2026
Merged

JE-Chen merged 1 commit into
devfrom
ci-fixes-137

Conversation

@JE-Chen

@JE-Chen JE-Chen commented Sep 25, 2026

Copy link
Copy Markdown
Member

Codacy and SonarCloud failed on #137 (dev to main). All but one finding are false positives, marked inline the way the repo already does (# nosec / # nosemgrep / # NOSONAR with a reason):

  • Bandit B105 / Sonar S2068 on the SSH passphrase label, placeholder and message strings (en, zh-TW): UI text, not credentials.
  • Opengrep gitleaks private-key on _PKCS8_PLAIN: the PEM header used to recognise a PKCS#8 file, not a key.
  • Sonar S2583 on _exact_float: Decimal compares by value, so the condition is false for any number that round-trips.

The real one: main_ui.py kept the window in an unused local (F841). It is now released explicitly after exec(), which keeps the same lifetime.

Related tests pass locally (375).

…e UI text, the PKCS#8 header is a format marker, the main window reference is released explicitly after exec
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@sonarqubecloud

Copy link
Copy Markdown

@JE-Chen
JE-Chen merged commit 10344e3 into dev Sep 25, 2026
8 checks passed
@JE-Chen
JE-Chen deleted the ci-fixes-137 branch September 25, 2026 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant