Skip to main content

Security oriented static analyser for python code.

Project description

Build Status Docs Status Latest Version Python Versions Format License

A security linter from PyCQA


Bandit is a tool designed to find common security issues in Python code. To do this Bandit processes each file, builds an AST from it, and runs appropriate plugins against the AST nodes. Once Bandit has finished scanning all the files it generates a report.

Bandit was originally developed within the OpenStack Security Project and later rehomed to PyCQA.

Show Your Style

Security Status

Use our badge in your project’s README!

using Markdown:

[![security: bandit](](

using RST:

.. image::
    :alt: Security Status


Python AST module documentation:

Green Tree Snakes - the missing Python AST docs:

Documentation of the various types of AST nodes that Bandit currently covers or could be extended to cover:

Project details

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

bandit-1.7.4.tar.gz (495.1 kB view hashes)

Uploaded source

Built Distribution

bandit-1.7.4-py3-none-any.whl (118.3 kB view hashes)

Uploaded py3

Supported by

AWS AWS Cloud computing Datadog Datadog Monitoring Facebook / Instagram Facebook / Instagram PSF Sponsor Fastly Fastly CDN Google Google Object Storage and Download Analytics Huawei Huawei PSF Sponsor Microsoft Microsoft PSF Sponsor NVIDIA NVIDIA PSF Sponsor Pingdom Pingdom Monitoring Salesforce Salesforce PSF Sponsor Sentry Sentry Error logging StatusPage StatusPage Status page