Skip to main content

bandit-multi-format

Provides a multi output formatter for Bandit that writes the same Bandit report in multiple formats (e.g. json, txt, xml). This is a small solution for https://github.com/PyCQA/bandit/issues/447.

Purpose

When you want Bandit to produce multiple output formats from a single run, the multi formatter will call the configured Bandit formatters and write one output file per format.

Install

Install from PyPI in your Bandit environment:

pip install bandit-multi-format

In case of using pipx to manage Bandit installation, you can inject the package into the existing Bandit pipx environment:

pipx inject bandit bandit-multi-format

Usage

The multi formatter requires one environment variable to be set:

  • BANDIT_MULTI_FORMATS (required): comma-separated list of Bandit formatter names to invoke (for example: json,txt).

Optional environment variable:

  • BANDIT_MULTI_OUTPUT_DIR (optional): path to a directory where all outputs will be written. If not set, the formatter attempts to determine an output directory from Bandit's output file object (for example, when Bandit is run with -o /path/to/outfile it will use that file's parent directory). If neither is available, the formatter raises an error asking you to set BANDIT_MULTI_OUTPUT_DIR.

Notes:

  • The special format name multi cannot be used inside BANDIT_MULTI_FORMATS (the package blocks it to avoid recursion).
  • Output files are written as bandit_output.<format> (for example: bandit_output.json, bandit_output.txt) in the chosen output directory.

Example usage (write JSON and TXT outputs to ./bandit_outputs):

export BANDIT_MULTI_FORMATS="json,txt"
export BANDIT_MULTI_OUTPUT_DIR="./bandit_outputs"
bandit -r path/to/project -f multi

If you prefer to let the formatter infer the output directory from Bandit's -o option, provide an output file when running Bandit:

export BANDIT_MULTI_FORMATS="json,txt"
bandit -r path/to/project -f multi -o ./reports/bandit_report.out
# This will create ./reports/bandit_output.json and ./reports/bandit_output.txt

Warning about using -o:

  • The directory for the -o file must exist beforehand — Bandit will not create parent directories for the output file.
  • Using -o can be confusing with the multi formatter because Bandit itself will open (and typically create/truncate) the -o file before formatters run. That means an empty file may be created at the -o path. In some cases this results in an extra empty file unless the -o filename matches what a formatter would write itself.

In practice: if you want clean outputs in a specific folder, it's often simpler to set BANDIT_MULTI_OUTPUT_DIR to the desired directory instead of relying on -o.

If you run Bandit without -o and without setting BANDIT_MULTI_OUTPUT_DIR, the multi formatter will raise an error and ask you to set BANDIT_MULTI_OUTPUT_DIR.

Examples and troubleshooting

  • Make sure each format listed in BANDIT_MULTI_FORMATS is a valid Bandit formatter available in your environment. The multi formatter will skip formats it cannot load and log errors.

Implementation notes

  • See src/bandit_multi_format/__init__.py for details: the formatter loads Bandit's registered formatters and calls each one, creating bandit_output.<fmt> files in the chosen directory.

Metadata

Release files for bandit-multi-format 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bandit-multi-format 0.1.1
File Size Uploaded
bandit_multi_format-0.1.1.tar.gz 4.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bandit-multi-format 0.1.1
File Interpreter ABI Platform
bandit_multi_format-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 9.1 kB

Release files / bandit_multi_format-0.1.1.tar.gz

Download URL bandit_multi_format-0.1.1.tar.gz
Size 4.1 kB
Tags Source
SHA-256 checksum
How to use checksums
7788908fc071ea965ccc327a5f746999afab19cb915b11550f7dee72c5decd81
BLAKE2b-256 checksum
How to use checksums
6ac9614d17570cfdb0c8a474f5bab8b2257c6676771ed5d944a40461825e79c9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / bandit_multi_format-0.1.1-py3-none-any.whl

Download URL bandit_multi_format-0.1.1-py3-none-any.whl
Size 4.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
936613de0a82f60921a2e75f29d0014d8e987321a8afa8dcbe691833f406d30f
BLAKE2b-256 checksum
How to use checksums
987ab9386642908c02d6ee46652ffc33e58348c1a9a3e9dff02013b3202a8ac4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page