Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/tylerwince/flake8-bandit
Automated security testing using bandit and flake8.
https://github.com/tylerwince/flake8-bandit
bandit flake8 security security-automation security-tools static-code-analysis vulnerability-detection
Last synced: 3 months ago
JSON representation
Automated security testing using bandit and flake8.
- Host: GitHub
- URL: https://github.com/tylerwince/flake8-bandit
- Owner: tylerwince
- License: mit
- Created: 2017-10-28T23:19:09.000Z (about 7 years ago)
- Default Branch: main
- Last Pushed: 2023-09-13T06:38:29.000Z (about 1 year ago)
- Last Synced: 2024-07-18T22:17:29.030Z (4 months ago)
- Topics: bandit, flake8, security, security-automation, security-tools, static-code-analysis, vulnerability-detection
- Language: Python
- Size: 86.9 KB
- Stars: 111
- Watchers: 5
- Forks: 25
- Open Issues: 12
-
Metadata Files:
- Readme: README.md
- License: LICENSE
- Security: SECURITY.md
Awesome Lists containing this project
- awesome-flake8-extensions - flake8-bandit - Wrapper around [bandit](https://github.com/PyCQA/bandit). (Wrappers)
README
# flake8-bandit
[![Build Status](https://travis-ci.org/tylerwince/flake8-bandit.svg?branch=master)](https://travis-ci.org/tylerwince/flake8-bandit)Automated security testing built right into your workflow!
You already use flake8 to lint all your code for errors, ensure docstrings are formatted correctly, sort your imports correctly, and much more... so why not ensure you are writing secure code while you're at it? If you already have flake8 installed all it takes is `pip install flake8-bandit`.
## Configuration
To include or exclude tests, use the standard `.bandit` configuration file. An example valid `.bandit` config file:
```text
[bandit]
exclude = /frontend,/scripts,/tests,/venv
tests: B101
```In this case, we've specified to ignore a number of paths, and to only test for B101.
**Note:** flake8-bugbear uses bandit default prefix 'B' so this plugin replaces the 'B' with an 'S' for Security. For more information, see https://github.com/PyCQA/flake8-bugbear/issues/37
## How's it work?
We use the [bandit](https://github.com/PyCQA/bandit) package from [PyCQA](https://meta.pycqa.org/#) for all the security testing.