Repository navigation
[flake8-bandit] fix S113 false positive for httpx without timeout argument - #12213
Merged
Merged
Conversation
This was referenced Jul 6, 2024
Contributor
|
We should also probably update the fixture to move the calls that don't pass |
Contributor
Author
make sense |
timeout argumentflake8-bandit] fix S113 false positive for httpx without timeout argument
Member
|
Thank you! Sorry that we missed this initially. |
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 19, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 19, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 19, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 19, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 20, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 20, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
itsvedantkumar
added a commit
to itsvedantkumar/ruff
that referenced
this pull request
Aug 20, 2026
The rule's docs said it checks `requests` or `httpx` calls that omit `timeout`. That has not been true for httpx since astral-sh#12213: omitting the argument is fine there, and only an explicit `timeout=None` is reported. The implementation only reports the implicit case when the module is `requests`. Assisted-by: Claude (Anthropic)
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 20, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 20, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 20, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 21, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 21, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 21, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 21, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 21, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 22, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 23, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 23, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 24, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 25, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 25, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 26, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 26, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 27, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 27, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 28, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 28, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 29, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 29, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 30, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Aug 31, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
vitorantoniazzi
added a commit
to vitorantoniazzi/ruff
that referenced
this pull request
Sep 2, 2026
The rule stopped flagging `httpx` calls that omit `timeout` in astral-sh#12213, since httpx applies a default timeout. Update the documentation to describe what the rule actually checks.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Sep 5, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Sep 6, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Sep 6, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
ayaangazali
added a commit
to ayaangazali/ruff
that referenced
this pull request
Sep 12, 2026
…al-sh#27868) The docs say the rule checks `requests` or `httpx` calls that omit the `timeout` parameter. That has not been true for `httpx` since astral-sh#12213, which stopped reporting on it because `httpx` already applies a five second timeout by default, so omitting the parameter is not a hang risk there. The description also never mentioned the case the rule does still check for both modules, an explicit `timeout=None`, even though the violation message has a separate wording for it. Describe what the rule actually does: `requests` calls that omit `timeout`, and `requests` or `httpx` calls that pass `timeout=None`. Say why the two modules differ, so it is clear this is a deliberate distinction rather than a gap.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
S113 exists because
requestsdoesn't have a default timeout, so request without timeout may hang indefinitelyBut httpx has default timeout 5s, so S113 for httpx request without
timeoutargument is a false positive, only valid case would betimeout=None.https://www.python-httpx.org/advanced/timeouts/
Test Plan
snap updated