Description
password.py uses shell=True in subprocess.run() to execute the configured password command. This is by design (user configures the command in .vaultctl.yml), but bandit flags it as B602 (high severity).
Proposed Solution
Either:
- Add
B602 to bandit skips in pyproject.toml with a comment explaining why
- Or use
shlex.split() + shell=False (would break commands with pipes/redirects)
Option 1 is preferred since the command comes from a trusted config file.
Files
src/vaultctl/password.py (line 45)
pyproject.toml (bandit skips)
Priority
P2
Description
password.pyusesshell=Trueinsubprocess.run()to execute the configured password command. This is by design (user configures the command in.vaultctl.yml), but bandit flags it as B602 (high severity).Proposed Solution
Either:
B602to bandit skips inpyproject.tomlwith a comment explaining whyshlex.split()+shell=False(would break commands with pipes/redirects)Option 1 is preferred since the command comes from a trusted config file.
Files
src/vaultctl/password.py(line 45)pyproject.toml(bandit skips)Priority
P2