bandit
https://github.com/pycqa/bandit
Python
Bandit is a tool designed to find common security issues in Python code.
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Python not yet supported8 Subscribers
Add a CodeTriage badge to bandit
Help out
- Issues
- [Security] tarfile.extractall without member validation in examples/tarfile_extractall.py
- [pre-commit.ci] pre-commit autoupdate
- Update B313/B314 XML warning message for Python 3.11+
- Fix spurious nosec warnings on multiline statements
- Fix spurious nosec warning on f-strings with specific test IDs
- Update config docs to reflect current as-is behaviour (#528)
- pysnmp under new ownership with breaking compatilbility
- B614 False Positive when using torch.jit.load
- not distinguishing sql statement with mixed stringbased query construction and sanitised parameterised sql query
- Broken JUnit-like XML report files
- Docs
- Python not yet supported