class Detector::Python::Cli

Overview

Detects Python command-line applications: programs that parse argv via argparse / getopt or a CLI framework (click, typer, fire, docopt, absl-py flags, Cleo). Gates the Python CLI analyzer, which surfaces the argv / option / env attack surface as cli:// endpoints.

Detection is intentionally import-anchored. A bare import sys (sys.argv) is far too common to treat as CLI evidence on its own, so it is only honored inside the analyzer when paired with a __main__ guard.

Defined in:

detector/detectors/python/cli.cr

Constant Summary

CLI_IMPORT_RE = /(?:^|\n)\s*(?:import|from)\s+(?:argparse|click|typer|fire|docopt|getopt|absl|cleo)\b/

Class Method Summary

Instance Method Summary

Instance methods inherited from class Detector

applicable?(filename : String) : Bool applicable?, base_relative_path(filename : String) : String base_relative_path, content_matches?(file_contents : String, markers : Regex) : Bool content_matches?, detect(filename : String, file_contents : String) : Bool detect, gemfile_dependency?(file_contents : String, gem_name : String) : Bool gemfile_dependency?, gemspec_dependency?(file_contents : String, gem_name : String) : Bool gemspec_dependency?, idempotent? : Bool idempotent?, logger : NoirLogger logger, name : String name, path_sensitive? : Bool path_sensitive?

Constructor methods inherited from class Detector

new(options : Hash(String, YAML::Any)) new

Macros inherited from class Detector

detector_for(tech, extensions = nil, basenames = nil, path_segments = nil, idempotent = nil) detector_for

Class Method Detail

def self.tech_name : String #

The tech name without needing an instance, so the registry can be read off the classes themselves rather than from a parallel list.


[View source]

Instance Method Detail

def applicable?(filename : String) : Bool #
Description copied from class Detector

Cheap filename-only filter the detector pass uses to skip #detect on files the detector cannot possibly match. The default true preserves prior behavior (every detector runs on every file). Override with the same predicate the body of #detect starts with — e.g., filename.ends_with?(".py") for a Python framework detector — so the detector loop avoids the #detect dispatch on files outside the detector's language.

On large codebases (saleor's 4255 .py files) this lifts ~100 virtual #detect calls per file out of the hot loop because most detectors' inner first-line is exactly this kind of cheap filename check.


[View source]
def detect(filename : String, file_contents : String) : Bool #

[View source]
def set_name #

[View source]