Repository navigation
Implement flake8-bandit #1646
Description
Activity
\cc @edgarrmondragon - easier to track here than to keep incrementing the count in the README. I'll populate the checklist.
Reacted by Edgar Ramírez Mondragón- addedpluginImplementing a known but unsupported Ruff pluginImplementing a known but unsupported Ruff plugin
on Jan 5, 2023 thanks @charliermarsh!
By the way: the scripts are pretty bad right now, but it might save you some time (and would love help improving):
python scripts/add_check.py --name ConvertLoopToAll --code SIM111 --plugin flake8-simplifyThe main limitations right now are:
- Doesn't keep the members sorted in
registry.rs, so has to be manually resorted (else checks appear out-of-order in the docs and elsewhere). - Assumes you're using a single
plugins.rsfile, instead of individual files for each check or achecks.rsfile or whatever else, so that also requires manual tweaks.
- Doesn't keep the members sorted in
By the way: the scripts are pretty bad right now, but it might save you some time (and would love help improving):
python scripts/add_check.py --name ConvertLoopToAll --code SIM111 --plugin flake8-simplifyThe main limitations right now are:
- Doesn't keep the members sorted in
registry.rs, so has to be manually resorted (else checks appear out-of-order in the docs and elsewhere). - Assumes you're using a single
plugins.rsfile, instead of individual files for each check or achecks.rsfile or whatever else, so that also requires manual tweaks.
Thanks, I'll take a look at those. They might be really helpful for bandit's blacklist tests.
- Doesn't keep the members sorted in
- added 4 commits that reference this issue
on Jan 5, 2023 Please implement the configurations for it as well e.g
exclude_dirs.https://bandit.readthedocs.io/en/latest/config.html#bandit-settings
@ahmedbilal - I think
exclude_dirscan be accomplished with theper-file-ignoressettings, like:[tool.ruff.per-file-ignores] "excluded_dir" = ["S"]
Reacted by Niko FöhrNot sure if this is the best place to ask, but do flake8-bandit and bandit have the same linters?
Also @charliermarsh do you think it would be helpful to pin all of the issues that are trackers for implementing a package to the top? It would make it easier for people to understand our progress, and to contribute to one.
71 remaining items
- added 14 commits that reference this issue
on May 1, 2026 - added a commit that references this issue
on Sep 13, 2026
S101:assert_usedS102:exec_usedS103:set_bad_file_permissionsS104:hardcoded_bind_all_interfacesS105:hardcoded_password_stringS106:hardcoded_password_funcargS107:hardcoded_password_defaultS108:hardcoded_tmp_directoryS109:password_config_option_not_marked_secretS110:try_except_passS111:execute_with_run_as_root_equals_trueS112:try_except_continueS113:request_without_timeoutS201:flask_debug_trueS202:tarfile_unsafe_membersS301:pickleS302:marshalS303:md5S304:ciphersS305:cipher_modesS306:mktemp_qS307:evalS308:mark_safeS311:randomS312:telnetlibS313:xml_bad_cElementTreeS314:xml_bad_ElementTreeS315:xml_bad_expatreaderS316:xml_bad_expatbuilderS317:xml_bad_saxS318:xml_bad_minidomS319:xml_bad_pulldomS320:xml_bad_etreeS321:ftplibS323:unverified_contextS324:hashlibS310:urllib_urlopenS401:import_telnetlibS402:import_ftplibS403:import_pickleS404:import_subprocessS405:import_xml_etreeS406:import_xml_saxS407:import_xml_expatS408:import_xml_minidomS409:import_xml_pulldomS410:import_lxmlS411:import_xmlrpclibS412:import_httpoxyS413:import_pycryptoS415:import_pyghmiS501:request_with_no_cert_validationS502:ssl_with_bad_versionS503:ssl_with_bad_defaultsS504:ssl_with_no_versionS505:weak_cryptographic_keyS506:yaml_loadS507:ssh_no_host_key_verificationS508:snmp_insecure_versionS509:snmp_weak_cryptographyS601:paramiko_callsS602:subprocess_popen_with_shell_equals_trueS603:subprocess_without_shell_equals_trueS604:any_other_function_with_shell_equals_trueS605:start_process_with_a_shellS606:start_process_with_no_shellS607:start_process_with_partial_pathS608:hardcoded_sql_expressionsS609:linux_commands_wildcard_injectionS610:django_extra_usedS611:django_rawsql_usedS612:logging_config_insecure_listenS701:jinja2_autoescape_falseS702:use_of_mako_templatesS703:django_mark_safe