Skip to content

Return copied backend capability rows#3700

Open
FlorianPfaff wants to merge 2 commits into
mainfrom
bugfix/copy-backend-capability-rows
Open

Return copied backend capability rows#3700
FlorianPfaff wants to merge 2 commits into
mainfrom
bugfix/copy-backend-capability-rows

Conversation

@FlorianPfaff

Copy link
Copy Markdown
Owner

Summary

  • return copied row dictionaries from iter_api_backend_capabilities() instead of exposing live registry rows
  • add a regression test that mutating an iterator row does not mutate API_BACKEND_CAPABILITIES

Bug fixed

iter_api_backend_capabilities() previously returned the dictionaries stored in API_BACKEND_CAPABILITIES directly. Any caller that adjusted a returned row could accidentally mutate the process-global backend capability registry, unlike the other public capability accessors that already return copies.

Validation

  • Inspected main..bugfix/copy-backend-capability-rows: 2 files changed, +12/-1.
  • Added test_iter_api_backend_capabilities_returns_row_copies in tests/test_backend_capabilities.py.
  • Full tests were not run locally because this environment could not clone/install from GitHub.

@FlorianPfaff FlorianPfaff enabled auto-merge (squash) July 2, 2026 16:56
@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ COPYPASTE jscpd yes no no 79.37s
✅ JSON prettier 7 0 0 0 1.11s
✅ JSON v8r 7 0 0 4.3s
✅ MARKDOWN markdownlint 68 0 0 0 1.99s
✅ MARKDOWN markdown-table-formatter 68 0 0 0 1.09s
✅ PYTHON black 1202 36 0 0 69.25s
✅ PYTHON isort 1202 68 0 0 3.21s
✅ REPOSITORY checkov yes no no 53.82s
✅ REPOSITORY gitleaks yes no no 11.68s
✅ REPOSITORY git_diff yes no no 0.29s
✅ REPOSITORY secretlint yes no no 56.83s
✅ REPOSITORY syft yes no no 5.35s
✅ REPOSITORY trivy-sbom yes no no 5.26s
✅ REPOSITORY trufflehog yes no no 15.69s
✅ YAML prettier 11 0 0 0 0.76s
✅ YAML v8r 11 0 0 12.01s
✅ YAML yamllint 11 0 0 0.62s

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.5.0 --custom-flavor-setup --custom-flavor-linters PYTHON_BLACK,PYTHON_ISORT,COPYPASTE_JSCPD,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant