Suppress noisy pip warnings in pre-commit hook

--no-warn-script-location: bandit scripts go to /tmp/.local/bin which is
not on PATH, but we invoke via 'python -m bandit' so this is harmless.
PIP_DISABLE_PIP_VERSION_CHECK=1: silence the version upgrade notice.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
curo1305
2026-04-13 23:05:00 +02:00
parent fd95459fc9
commit 5f306d7edc
+2 -1
View File
@@ -21,8 +21,9 @@ docker run --rm \
-e STAGED_FILES="$STAGED" \ -e STAGED_FILES="$STAGED" \
-u 1001:1001 \ -u 1001:1001 \
-e HOME=/tmp \ -e HOME=/tmp \
-e PIP_DISABLE_PIP_VERSION_CHECK=1 \
python:3.12-slim \ python:3.12-slim \
sh -c "pip install --quiet --user bandit && python scripts/security_check.py" sh -c "pip install --quiet --user --no-warn-script-location bandit && python scripts/security_check.py"
EXIT_CODE=$? EXIT_CODE=$?