bandit
https://github.com/pycqa/bandit
Python
Bandit is a tool designed to find common security issues in Python code.
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Python not yet supported6 Subscribers
Add a CodeTriage badge to bandit
Help out
- Issues
- #640 - Exit zero status based on severity level
- Possible hardcoded password: ''
- XML (JUnit) output is not recognized by Bamboo JUnit parser
- Error message refers to "defusedxml.defuse_stdlib()" but calling that does not silence bandit
- B405 complains about any xml.etree.ElementTree import, not just parse-related ones
- It would be useful to declare skips at module-level
- Official Dockerhub image
- Control report severity level separately to exit code
- ini "exclude" config is ignored
- Fix settings from INI file are overriden by default values
- Docs
- Python not yet supported