Codacy flagged two Bandit findings in the docset generator added in
#5799: B310 (urlopen with an unchecked scheme) and B506 (yaml.load).
download() now rejects anything but http(s) URLs before opening them,
and the yaml.load call is marked, since its Loader derives from
yaml.SafeLoader. The SHA-1 used to name downloaded files is marked as
not used for security.
Signed-off-by: Niels Lohmann <mail@nlohmann.me>
Replace the hand-maintained docs/docset/docSet.sql and the bash/sed
Makefile recipe with docs/docset/generate_docset.py:
- The search index is generated from the mkdocs.yml nav and each page's
H1 and declaration. Pages documenting several entities (e.g.
JSON_HAS_CPP_11..26) get one entry per name; all non-API pages become
guides. New API pages no longer need a manual entry.
- Page titles are set from the index names.
- The docset is self-contained: the mermaid loader no longer points to
https://json.nlohmann.me/assets/..., the repository widget no longer
queries api.github.com, remaining remote images are downloaded, and
the build fails if any remote resource load remains.
- The CSS that hides the site navigation now uses Material's classes;
the element selectors lost against them, so the header was shown.
check_structure.py's docset check is replaced by running the generator
in `make style_check`.
Signed-off-by: Niels Lohmann <mail@nlohmann.me>