You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 77db695
Browse filesBrowse the repository at this point in the historyBrowse files
- tls_connect_probe.py: _split_top_level now models a SINGLE-LEVEL braced value matching the
production parser (connection_string_parser.py::_parse_braced_value) -- an inner `{` is a
literal (not a nested open) and a `{` is only a brace-open at a value's START, so
`Pwd={a{b};Encrypt=no` splits correctly and force_tls no longer emits a duplicate
`encrypt` that mssql_python.connect would reject. (The production parser cannot be imported
here: it pulls in mssql_python -> the native ddbc_bindings extension, which this standalone
probe must stay importable / unit-testable without.)
- audit_bundled_binaries.py::_openssl_range_ok: the upper bound is valid only as an EXCLUSIVE
`<` at numeric release 4.0(.0...) -- `<4`, `<4.0`, `<4.0.0`, `<4.0a0` pass; `<=4`, `<4.1`,
`<4.0.1` (each admitting some openssl 4.x) now correctly FAIL.
- audit_bundled_binaries.py: an unknown `linux-*` subdir with no _SUBDIR_MACHINE mapping now
FAILS CLOSED instead of proceeding with expected_machine=None and silently skipping the ELF
architecture gate.
- _conda_pkg.py::iter_payload_members: a `.conda` missing its pkg-*.tar.zst now RAISES (was a
bare `return` -> silent empty iteration); both audit scripts convert that to a violation.
The Medium (the job-level TLS secret never reaching the posix `bash:` step) is already
resolved: the live Encrypt=yes gate was removed from the build pipeline entirely in the
previous commit (it moves to the release pipeline, where the secret is always present so the
gate is unconditional).
+7 unit tests (119 pass). black + flake8 clean; mypy clean on the scripts.
0 commit comments