Scan Python code for risky security patterns with Bandit before review or release
Catch insecure Python calls, weak crypto usage, shell injection risks, and similar patterns before merge or release.
Prerequisites
Bandit CLI, Python source tree
Installation
Use the upstream install or setup path that matches your environment:
- docker pull ghcr.io/pycqa/bandit/bandit
- docker pull --platform= ghcr.io/pycqa/bandit/bandit:latest
Requirements and caveats from upstream:
- :alt: Python Versions
- Bandit is a tool designed to find common security issues in Python code. To do
- Python AST module documentation: https://docs.python.org/3/library/ast.html
Basic usage or getting-started notes:
:alt: Bandit Example Screen Shot
Source: https://github.com/PyCQA/bandit
Extracted from upstream docs: https://raw.githubusercontent.com/PyCQA/bandit/HEAD/README.rst