Add bandit, use to catch known vulnerable XML parsing (#28341)

* Add bandit to pre-commit and CI, use to catch known vulnerable XML parsing

* Use defusedxml instead of direct xml.etree to parse XML

* Move config to tests/bandit.yaml
This commit is contained in:
Ville Skyttä 2019-11-18 10:10:15 +02:00 committed by Pascal Vizeli
parent aef808d2bf
commit d4c80f160c
13 changed files with 42 additions and 3 deletions

View file

@ -1,7 +1,7 @@
"""The tests for the rss_feed_api component."""
import asyncio
from xml.etree import ElementTree
from defusedxml import ElementTree
import pytest
from homeassistant.setup import async_setup_component