class
Detector::Python::Cli
- Detector::Python::Cli
- Detector
- Reference
- Object
Overview
Detects Python command-line applications: programs that parse argv via
argparse / getopt or a CLI framework (click, typer, fire, docopt, absl-py
flags, Cleo). Gates the Python CLI analyzer, which surfaces the argv /
option / env attack surface as cli:// endpoints.
Detection is intentionally import-anchored. A bare import sys
(sys.argv) is far too common to treat as CLI evidence on its own, so it
is only honored inside the analyzer when paired with a __main__ guard.
Defined in:
detector/detectors/python/cli.crConstant Summary
-
CLI_IMPORT_RE =
/(?:^|\n)\s*(?:import|from)\s+(?:argparse|click|typer|fire|docopt|getopt|absl|cleo)\b/
Instance Method Summary
-
#applicable?(filename : String) : Bool
Cheap filename-only filter the detector pass uses to skip
#detecton files the detector cannot possibly match. - #detect(filename : String, file_contents : String) : Bool
- #set_name
Instance methods inherited from class Detector
applicable?(filename : String) : Bool
applicable?,
detect(filename : String, file_contents : String) : Bool
detect,
gemfile_dependency?(file_contents : String, gem_name : String) : Bool
gemfile_dependency?,
gemspec_dependency?(file_contents : String, gem_name : String) : Bool
gemspec_dependency?,
idempotent? : Bool
idempotent?,
logger : NoirLogger
logger,
name : String
name,
path_sensitive? : Bool
path_sensitive?
Constructor methods inherited from class Detector
new(options : Hash(String, YAML::Any))
new
Instance Method Detail
Cheap filename-only filter the detector pass uses to skip
#detect on files the detector cannot possibly match. The
default true preserves prior behavior (every detector runs on
every file). Override with the same predicate the body of
#detect starts with — e.g., filename.ends_with?(".py") for a
Python framework detector — so the detector loop avoids the
#detect dispatch on files outside the detector's language.
On large codebases (saleor's 4255 .py files) this lifts ~100
virtual #detect calls per file out of the hot loop because
most detectors' inner first-line is exactly this kind of cheap
filename check.