Skip to content

[flake8-bandit] Describe what the rule actually checks for httpx (S113) - #1

Open
huyn7539 wants to merge 2 commits into
antelier-example/base-27936from
antelier-example/pr-27936
Open

huyn7539 wants to merge 2 commits into
antelier-example/base-27936from
antelier-example/pr-27936

Conversation

@huyn7539

@huyn7539 huyn7539 commented Sep 10, 2026 •

Copy link
Copy Markdown
Owner

Public Antelier example: replay of astral-sh#27936 at 060430d. This PR is only on the operator's fork; it proposes nothing upstream. Original description follows unchanged. The base snapshot preserves the original diff; only the Antelier workflow is added equally to both sides. Inherited upstream CI is not part of this Antelier example; some inherited jobs ran on the replay, and session-triggered unfinished jobs were cancelled. Agent attribution: Claude (body-reported assistance).


Hi :)

Summary

The S113 docs say it checks requests or httpx calls that omit timeout, but that hasn't been true for httpx sincee astral-sh#12213

httpx applies a default timeout, so leaving the argument out is fine there -- only an explicit timeout=None gets reported

In the code the implicit case is only reported when the module is requests

So this rewrites "What it does" & "Why is this bad?" to match what the rule actually does

Doc comment only, no behaviour change -- closes astral-sh#27868

Test Plan

Ran ruff 0.16.3 over three files:

  • httpx.get(url) -> nothing reported
  • httpx.get(url, timeout=None) -> S113, "timeout set to None"
  • requests.get(url) -> S113, "without timeout"

docs/rules is generated rather than committed, so there's nothing to regenerate here

Drafted with AI assistance (Claude Fable 5)

@github-actions

github-actions Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Claim check for #1 — 4 of 11 claims checked · 1 present · 3 partial

cannot tell — requests: cited text is documentation, not executed code

Quoted source (claim_27f906377800fefc0801, evidence: partial):

The S113 docs say it checks `requests` or `httpx` calls that omit `timeout`, but that hasn't been true for httpx sincee #12213

crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18

cannot tell — timeout=None: cited text is documentation, not executed code

Quoted source (claim_ff48a906056c2cc83cc4, evidence: partial):

httpx applies a default timeout, so leaving the argument out is fine there -- only an explicit `timeout=None` gets reported

crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18

cannot tell — httpx.get(url, timeout=None): cited text is documentation, not executed code

Quoted source (claim_08f67d9421e57a641a10, evidence: partial):

`httpx.get(url, timeout=None)` -> S113, "timeout set to `None`"

crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18

Claims vs diff (11)
# Claim (quoted from the PR) Label Evidence
1 The S113 docs say it checks requests or httpx calls that omit timeout, but that hasn't been true for httpx sincee astral-sh#12213
…/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18 View diff
partial cited text is documentation, not executed code
2 httpx applies a default timeout, so leaving the argument out is fine there -- only an explicit timeout=None gets reported
…/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18 View diff
partial same
3 httpx.get(url, timeout=None) -> S113, "timeout set to None"
…/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18 View diff
partial same
4 [flake8-bandit] Describe what the rule actually checks for httpx (S113)
…/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L17 View diff
present identifier appears in the expected changed hunk lines
—
7 not checkable (show)
  1. So this rewrites "What it does" & "Why is this bad?" to match what the rule actually does — not decidable from the available evidence
  2. Doc comment only, no behaviour change -- closes request-without-timeout (S113) - documentation incorrectly references httpx astral-sh/ruff#27868 — not decidable from the available evidence
  3. httpx.get(url) -> nothing reported — not decidable from the diff
  4. requests.get(url) -> S113, "without timeout" — not decidable from the diff
  5. docs/rules is generated rather than committed, so there's nothing to regenerate here — not decidable from the diff
  6. Replay astral-sh/ruff PR 27936: [flake8-bandit] Describe what the r… — not decidable from the available evidence
  7. Re-run Antelier claim check with antelier/action@v0 = v0.4.8 (engine … — not decidable from the available evidence
not checkable collapsed by default
—
1 context line (not claims, show)
  1. In the code the implicit case is only reported when the module is requests — context: describes state or cause, not a change this PR makes
context describes state or cause; never labelled

present: in the diff at the cited hunk · partial: some of it · absent: nothing in the diff corresponds · contradicted: the diff does the opposite · not checkable: not decidable from the diff

Attention (5)
  1. undisclosed-file — File changed but not mentioned in the PR body — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L7-L21
  2. partial — Partial claim — “The S113 docs say it checks requests or httpx calls that omit timeout, but that hasn't been true for httpx sincee [flake8-bandit] fix S113 false positive for httpx without timeout argument astral-sh/ruff#12213”; missing: executable code or test evidence for the claimed behaviour — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18
  3. partial — Partial claim — “httpx applies a default timeout, so leaving the argument out is fine there -- only an explicit timeout=None gets reported”; missing: executable code or test evidence for the claimed behaviour — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18
  4. partial — Partial claim — “httpx.get(url, timeout=None) -> S113, "timeout set to None"”; missing: executable code or test evidence for the claimed behaviour — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18
  5. ci-reported — CI — reported cargo build (msrv): queued, cargo clippy: queued, cargo fmt: queued, cargo fuzz build: queued, cargo publish dry-run: queued, cargo shear: queued, cargo test (linux): queued, cargo test (macos-latest): in_progress, cargo test (wasm): queued, cargo test (windows-latest): in_progress, ecosystem: queued, mkdocs: queued, plan: queued, prek: queued, python package: queued, test ruff-lsp: queued, test scripts: queued; reported, not observed by Antelier — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L7-L21
Author attestation — draft, confirm or edit

What changed: The S113 docs say it checks requests or httpx calls that omit timeout, but that hasn't been true for httpx sincee astral-sh#12213 — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18
Why: Why this change was made is not established by the excluded motivation text; confirm intent. — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18
What could break: No touched exported symbol establishes what could break; confirm callers or behavior at this diff. — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18
What was tested: No test evidence in this diff; confirm what was tested. — crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18

Confirming these under a maintainer's name happens on the hosted page, which is not part of the free action.

Rules applied (2) · Provenance

Propose a team rule from a reply on this PR, e.g. antelier: forbid legacyApi in src/** — the next run answers with a dry run against this diff and the YAML to commit.

Antelier's own rules on every comment: Claim labels use fetched patch bytes only; Citations are verified before rendering.
Provenance: Authorship: not reported

Rule version claim-check-rubric-v1 · JSON route /api/truth/v1/pr/1

Need a complete relevant diff, an applicable rule, or a reproducing test with its output to decide whether the description or code needs changing.

@huyn7539

Copy link
Copy Markdown
Owner Author

Re-run with antelier/action@v0 = v0.4.8 (engine 0d6cfa8c).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant