diff --git a/bandit/plugins/request_without_timeout.py b/bandit/plugins/request_without_timeout.py index 9aa80bfa8..a418b6cc0 100644 --- a/bandit/plugins/request_without_timeout.py +++ b/bandit/plugins/request_without_timeout.py @@ -52,10 +52,9 @@ @test.test_id("B113") def request_without_timeout(context): http_verbs = ("get", "options", "head", "post", "put", "patch", "delete") - if ( - "requests" in context.call_function_name_qual - and context.call_function_name in http_verbs - ): + qualname = context.call_function_name_qual.split(".")[0] + + if qualname == "requests" and context.call_function_name in http_verbs: # check for missing timeout if context.check_call_arg_value("timeout") is None: return bandit.Issue( diff --git a/examples/requests-missing-timeout.py b/examples/requests-missing-timeout.py index 75cb5a7ff..38f24440a 100644 --- a/examples/requests-missing-timeout.py +++ b/examples/requests-missing-timeout.py @@ -1,4 +1,5 @@ import requests +import not_requests requests.get('https://gmail.com') requests.get('https://gmail.com', timeout=None) @@ -21,3 +22,6 @@ requests.head('https://gmail.com') requests.head('https://gmail.com', timeout=None) requests.head('https://gmail.com', timeout=5) + +# Okay +not_requests.get('https://gmail.com')