Skip to main content

Security oriented static analyser for python code.

Project description

Build Status Docs Status Latest Version Python Versions Format License Discord

A security linter from PyCQA


Bandit is a tool designed to find common security issues in Python code. To do this Bandit processes each file, builds an AST from it, and runs appropriate plugins against the AST nodes. Once Bandit has finished scanning all the files it generates a report.

Bandit was originally developed within the OpenStack Security Project and later rehomed to PyCQA.

Bandit Example Screen Shot

Show Your Style

Security Status

Use our badge in your project’s README!

using Markdown:

[![security: bandit](](

using RST:

.. image::
    :alt: Security Status


Python AST module documentation:

Green Tree Snakes - the missing Python AST docs:

Documentation of the various types of AST nodes that Bandit currently covers or could be extended to cover:

Container Images

Bandit is available as a container image, built within the bandit repository using GitHub Actions. The image is available on

docker pull

The image is built for the following architectures:

  • amd64

  • arm64

  • armv7

  • armv8

To pull a specific architecture, use the following format:

docker pull --platform=<architecture>

Every image is signed with sigstore cosign and it is possible to verify the source of origin using the following cosign command:

cosign verify \
  --certificate-identity<version> \

Where <version> is the release version of Bandit.


The development of Bandit is made possible by the following sponsors:

Tidelift Stacklok Sentry

If you also ❤️ Bandit, please consider sponsoring.

Project details

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

bandit-1.7.9.tar.gz (4.2 MB view hashes)

Uploaded Source

Built Distribution

bandit-1.7.9-py3-none-any.whl (128.0 kB view hashes)

Uploaded Python 3

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page