Repository navigation
Conversation
…ule actually checks for `httpx` (`S113`)
Claim check for #1 — 4 of 11 claims checked · 1 present · 3 partialcannot tell — requests: cited text is documentation, not executed code Quoted source (claim_27f906377800fefc0801, evidence: partial): crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L10-L18 cannot tell — timeout=None: cited text is documentation, not executed code Quoted source (claim_ff48a906056c2cc83cc4, evidence: partial): crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18 cannot tell — httpx.get(url, timeout=None): cited text is documentation, not executed code Quoted source (claim_08f67d9421e57a641a10, evidence: partial): crates/ruff_linter/src/rules/flake8_bandit/rules/request_without_timeout.rs @@ -7,13 +7,15 @@ L11-L18 Claims vs diff (11)
present: in the diff at the cited hunk · partial: some of it · absent: nothing in the diff corresponds · contradicted: the diff does the opposite · not checkable: not decidable from the diff Attention (5)
Author attestation — draft, confirm or editWhat changed: The S113 docs say it checks Confirming these under a maintainer's name happens on the hosted page, which is not part of the free action. Rules applied (2) · ProvenancePropose a team rule from a reply on this PR, e.g. Antelier's own rules on every comment: Claim labels use fetched patch bytes only; Citations are verified before rendering. Rule version Need a complete relevant diff, an applicable rule, or a reproducing test with its output to decide whether the description or code needs changing. |
|
Re-run with antelier/action@v0 = v0.4.8 (engine 0d6cfa8c). |
…0d6cfa8c); no file changes
Hi :)
Summary
The S113 docs say it checks
requestsorhttpxcalls that omittimeout, but that hasn't been true for httpx sincee astral-sh#12213httpx applies a default timeout, so leaving the argument out is fine there -- only an explicit
timeout=Nonegets reportedIn the code the implicit case is only reported when the module is
requestsSo this rewrites "What it does" & "Why is this bad?" to match what the rule actually does
Doc comment only, no behaviour change -- closes astral-sh#27868
Test Plan
Ran ruff 0.16.3 over three files:
httpx.get(url)-> nothing reportedhttpx.get(url, timeout=None)-> S113, "timeout set toNone"requests.get(url)-> S113, "without timeout"docs/rulesis generated rather than committed, so there's nothing to regenerate hereDrafted with AI assistance (Claude Fable 5)