Sonarqube rule| Using command line arguments is security-sensitive for Python Application

Viewed 71

I want to use the command line arguments for one of my application, But Sonarqube is showing the code issue and recommending to sanitize it. Can anyone suggest how to resolve this ? Sonarqube is showing issue in this line -

execute_from_command_line(sys.argv)

I already tried putting sys.argv in some variable and then using it function calls. But it didn't helped.

I am using following versions:

Python : 3.9.10

Sonar-Scanner : 4.6.2.2472

1 Answers

For safety purposes, always check that only expected or allowed commands are coming from sys.argv .

If anyother command is passed, do not execute those commands.

Even if you add the above validation, sonarqube might throw error.

In the sonar rule doc, it is mentioned that this rule will be deprecated in future.

Related