bandit
https://github.com/pycqa/bandit
Python
Bandit is a tool designed to find common security issues in Python code.
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Python not yet supported6 Subscribers
Add a CodeTriage badge to bandit
Help out
- Issues
- Excluded paths from the .ini file ignored if -x flag is set
- standard code suggestion from psycopg gets errors
- do not trigger hardcoded password on empty string, #714
- Option to output violation information of skipped tests/lines
- Add config via setup.cfg
- Error parsing pyproject.tml
- Bandit fails when running as part of pre-commit
- Any chance of supporting sonarqube plugin?
- SQL Injection flagged when concatenating strings
- B410: lxml.cssselect has no equivalent in defusedxml
- Docs
- Python not yet supported