flake8-bandit 4.1.1


pip install flake8-bandit

  Latest version

Released: Aug 29, 2022

Project Links

Meta
Author: Tyler Wince
Requires Python: >=3.6

Classifiers

Framework
  • Flake8

Environment
  • Console

Intended Audience
  • Developers

License
  • OSI Approved :: MIT License

Programming Language
  • Python
  • Python :: 3

Topic
  • Security
  • Software Development :: Libraries :: Python Modules
  • Software Development :: Quality Assurance

flake8-bandit

Build Status

Automated security testing built right into your workflow!

You already use flake8 to lint all your code for errors, ensure docstrings are formatted correctly, sort your imports correctly, and much more... so why not ensure you are writing secure code while you're at it? If you already have flake8 installed all it takes is pip install flake8-bandit.

Configuration

To include or exclude tests, use the standard .bandit configuration file. An example valid .bandit config file:

[bandit]
exclude = /frontend,/scripts,/tests,/venv
tests: B101

In this case, we've specified to ignore a number of paths, and to only test for B101.

Note: flake8-bugbear uses bandit default prefix 'B' so this plugin replaces the 'B' with an 'S' for Security. For more information, see https://github.com/PyCQA/flake8-bugbear/issues/37

How's it work?

We use the bandit package from PyCQA for all the security testing.

Wheel compatibility matrix

Platform Python 3
any

Files in release

Extras: None
Dependencies:
flake8 (>=5.0.0)
bandit (>=1.7.3)