fix(worker): bandit/ruff 合规:用 httpx 替换 urllib,subprocess 加 nosec
CI/CD Pipeline / Dedup Check - skip PR tests when covered by push pipeline (pull_request) Successful in 1s
CI/CD Pipeline / Check push changed paths (pull_request) Has been skipped
CI/CD Pipeline / Check if frontend-only change (pull_request) Successful in 1s
PR Automation / Auto Approve on CI Green (pull_request) Successful in 2m49s
Preview Deploy / Deploy Preview Environment (pull_request) Successful in 4m23s
CI/CD Pipeline / Frontend Lint (pull_request) Has been skipped
CI/CD Pipeline / Frontend Unit Tests (pull_request) Has been skipped
CI/CD Pipeline / PR Build API Image (pull_request) Successful in 16s
CI/CD Pipeline / PR Build Web Image (pull_request) Has been skipped
AI Code Review / AI Code Review (pull_request) Successful in 7m4s
CI/CD Pipeline / Build Staging API Image (pull_request) Has been skipped
CI/CD Pipeline / Build Staging Web Image (pull_request) Has been skipped
CI/CD Pipeline / Build Staging Worker Image (pull_request) Has been skipped
CI/CD Pipeline / PR Build Worker Image (pull_request) Successful in 3m1s
CI/CD Pipeline / Retag skipped Staging API Image (pull_request) Has been skipped
CI/CD Pipeline / Retag skipped Staging Web Image (pull_request) Has been skipped
CI/CD Pipeline / Retag skipped Staging Worker Image (pull_request) Has been skipped
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Has been skipped
CI/CD Pipeline / Staging E2E Tests (pull_request) Has been skipped
CI/CD Pipeline / Staging API Integration Tests (pull_request) Has been skipped
CI/CD Pipeline / ACR Image Cleanup (pull_request) Has been skipped
PR Automation / Auto Merge on CI Green + Approved (pull_request) Successful in 10m41s
CI/CD Pipeline / Integration Tests (pull_request) Successful in 25m23s
CI/CD Pipeline / Unit Tests (pull_request) Has been cancelled
CI/CD Pipeline / Build Production API Image (pull_request) Has been cancelled
CI/CD Pipeline / Build Production Web Image (pull_request) Has been cancelled
CI/CD Pipeline / Build Production Worker Image (pull_request) Has been cancelled
CI/CD Pipeline / Deploy Production (pull_request) Has been cancelled
CI/CD Pipeline / Production Browser E2E (pull_request) Has been cancelled
CI/CD Pipeline / Canary Release to Production (pull_request) Has been cancelled
CI/CD Pipeline / CI Gate (pull_request) Has been cancelled
CI/CD Pipeline / Validate - Style (pull_request) Has been cancelled
CI/CD Pipeline / Validate - Python (mypy + alembic) (pull_request) Has been cancelled
CI/CD Pipeline / Validate - Security (pull_request) Has been cancelled

This commit is contained in:
xiaoxia
2026-09-29 20:47:16 +08:00
parent df0cc0c1b5
commit 68293eb79b
+13 -9
View File
@@ -24,7 +24,7 @@ import json
import logging
import math
import shutil
import subprocess
import subprocess # nosec B404
import tempfile
import uuid
from dataclasses import dataclass, field
@@ -134,7 +134,7 @@ def _probe_duration(video_path: str | Path) -> float:
stderr=subprocess.DEVNULL,
timeout=10,
text=True,
)
) # nosec B603
return float(out.strip() or 0)
except Exception as exc: # noqa: BLE001
logger.warning("ffprobe 时长探测失败 %s: %s", video_path, exc)
@@ -159,7 +159,7 @@ def _extract_keyframes(video_path: Path, out_dir: Path, interval: int = KEYFRAME
]
subprocess.run(
cmd_fixed, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, timeout=DEFAULT_ANALYSIS_TIMEOUT, check=False
)
) # nosec B603
# 场景切换帧(独立命名,scene_ 前缀)
scene_tpl = str(out_dir / "scene_%04d.jpg")
cmd_scene = [
@@ -177,7 +177,7 @@ def _extract_keyframes(video_path: Path, out_dir: Path, interval: int = KEYFRAME
]
subprocess.run(
cmd_scene, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, timeout=DEFAULT_ANALYSIS_TIMEOUT, check=False
)
) # nosec B603
frames = sorted(out_dir.glob("f_*.jpg")) + sorted(out_dir.glob("scene_*.jpg"))
# 去重(时间点相近时 scene 帧和 fixed 帧可能重复,简单按文件名存在性保留)
seen: set[str] = set()
@@ -332,7 +332,7 @@ def _detect_bpm(video_path: Path) -> int:
stderr=subprocess.DEVNULL,
timeout=20,
check=False,
)
) # nosec B603
if not tmp_wav.exists() or tmp_wav.stat().st_size < 1024:
return 0
y, sr = librosa.load(str(tmp_wav), sr=22050, mono=True)
@@ -415,7 +415,7 @@ def _upload_frames_to_oss(frame_paths: list[Path]) -> list[str]:
continue
b64 = base64.b64encode(p.read_bytes()).decode("ascii")
urls.append(f"data:image/jpeg;base64,{b64}")
except Exception: # noqa: BLE001
except Exception: # noqa: BLE001 # nosec B112
continue
return urls
@@ -867,11 +867,15 @@ def _ensure_local_video(reference: str, work_dir: Path) -> Optional[Path]:
logger.warning("download_asset 失败,尝试 http 直连: %s", exc)
if reference.startswith(("http://", "https://")):
try:
import urllib.request
import httpx # noqa: PLC0415 - 项目依赖,延迟导入
target = work_dir / f"ref_{uuid.uuid4().hex}.mp4"
with urllib.request.urlopen(reference, timeout=20) as r, open(target, "wb") as f:
shutil.copyfileobj(r, f)
with httpx.Client(timeout=20.0, follow_redirects=True) as client:
with client.stream("GET", reference) as resp:
resp.raise_for_status()
with open(target, "wb") as f:
for chunk in resp.iter_bytes(chunk_size=64 * 1024):
f.write(chunk)
if target.exists() and target.stat().st_size > 0:
return target
except Exception as exc: # noqa: BLE001