bandit
https://github.com/pycqa/bandit
Python
Bandit is a tool designed to find common security issues in Python code.
Triage Issues!
When you volunteer to triage issues, you'll receive an email each day with a link to an open issue that needs help in this project. You'll also receive instructions on how to triage issues.
Triage Docs!
Receive a documented method or class from your favorite GitHub repos in your inbox every day. If you're really pro, receive undocumented methods or classes and supercharge your commit history.
Python not yet supported8 Subscribers
Add a CodeTriage badge to bandit
Help out
- Issues
- Recognize safe extraction filters and fix member call handling in B202
- Honor quiet flag for early startup log messages
- Detect local subclasses of Markup in B704
- fix(cli): clamp severity/confidence counts to valid ranking range
- B202: detect tarfile extractall imported via a from-import
- fix(B614): suppress false positive on non-literal weights_only; add torch.jit.load regression coverage
- Fixes #1397
- Detect empty string socket binds in B104
- Clarify Bandit Python version guidance
- Add README installation guidance
- Docs
- Python not yet supported