Skip to main content

Combine multiple popular python security tools and generate reports or output into different formats

Project description

Github top language Codacy grade Repository size Issues License Commit activity Last commit PyPI Downloads PyPI Version

SimpleSecurity

Project Icon

Combine multiple popular python security tools and generate reports or output into different formats

Plugins (these require the plugin executable in the system path. e.g. bandit requires bandit to be in the system path...)

  • bandit
  • safety
  • dodgy
  • dlint

Formats

  • ansi (for terminal)
  • json
  • markdown
  • csv

Example Use

See below for the output if you run simplesecurity in this directory

Help

usage: __main__.py [-h] [--format FORMAT] [--plugin PLUGIN] [--file FILE] [--level LEVEL] [--confidence CONFIDENCE]
                   [--no-colour] [--high-contrast] [--fast]

Combine multiple popular python security tools and generate reports or output
into different formats

optional arguments:
  -h, --help            show this help message and exit
  --format FORMAT, -f FORMAT
                        Output format. One of ansi, json, markdown, csv. default=ansi
  --plugin PLUGIN, -p PLUGIN
                        Plugin to use. One of bandit, safety, dodgy, dlint, pygraudit, semgrep, all, default=all
  --file FILE, -o FILE  Filename to write to (omit for stdout)
  --level LEVEL, -l LEVEL
                        Minimum level/ severity to show
  --confidence CONFIDENCE, -c CONFIDENCE
                        Minimum confidence to show
  --no-colour, -z       No ANSI colours
  --high-contrast, -Z   High contrast colours
  --fast, --skip        Skip long running jobs. Will omit plugins with long run time (applies to -p all only)

You can also import this into your own project and use any of the functions in the DOCS

Table of Contents

Changelog

See the CHANGELOG for more information.

Install With PIP

"Slim" Build: Install bandit, dlint, dodgy, poetry, and safety with pipx

pip install simplesecurity

Otherwise:

pip install simplesecurity[full]

Head to https://pypi.org/project/SimpleSecurity/ for more info

Developer Notes

Generate semgrep_sec.yaml

  1. Clone https://github.com/returntocorp/semgrep-rules
  2. cd to project/python
  3. do
    $ cat **/security/**/*.yaml >> semgrep_sec.yaml
    $ cat **/security/*.yaml >> semgrep_sec.yaml
    
  4. Find and replace rules: with `` apart from the first instance
  5. Reformat with ctrl+shift+i
  6. replace simplesecurity/semgrep_sec.yaml with the new one

Language information

Built for

This program has been written for Python 3 and has been tested with Python version 3.9.0 https://www.python.org/downloads/release/python-380/.

Install Python on Windows

Chocolatey

choco install python

Download

To install Python, go to https://www.python.org/ and download the latest version.

Install Python on Linux

Apt

sudo apt install python3.9

How to run

With VSCode

  1. Open the .py file in vscode
  2. Ensure a python 3.9 interpreter is selected (Ctrl+Shift+P > Python:Select Interpreter > Python 3.9)
  3. Run by pressing Ctrl+F5 (if you are prompted to install any modules, accept)

From the Terminal

./[file].py

Community Files

Licence

MIT License Copyright (c) FredHappyface (See the LICENSE for more information.)

Changelog

See the Changelog for more information.

Code of Conduct

In the interest of fostering an open and welcoming environment, we as contributors and maintainers pledge to make participation in our project and our community a harassment-free experience for everyone. Please see the Code of Conduct for more information.

Contributing

Contributions are welcome, please see the Contributing Guidelines for more information.

Security

Thank you for improving the security of the project, please see the Security Policy for more information.

Support

Thank you for using this project, I hope it is of use to you. Please be aware that those involved with the project often do so for fun along with other commitments (such as work, family, etc). Please see the Support Policy for more information.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

simplesecurity-2020.4.0.tar.gz (33.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

simplesecurity-2020.4.0-py3-none-any.whl (33.1 kB view details)

Uploaded Python 3

File details

Details for the file simplesecurity-2020.4.0.tar.gz.

File metadata

  • Download URL: simplesecurity-2020.4.0.tar.gz
  • Upload date:
  • Size: 33.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.1.3 CPython/3.9.0 Windows/10

File hashes

Hashes for simplesecurity-2020.4.0.tar.gz
Algorithm Hash digest
SHA256 463bcd8b7e15a63b8634ee134bc802325088aa6fd99cad0dd1956f994b8943f4
MD5 840fd61e2a8e7e3d8ddfddd6f88f453a
BLAKE2b-256 b273dc5d43182544620d5e472a53c70acc2d1efcd4ccebaa80662a60355d558f

See more details on using hashes here.

File details

Details for the file simplesecurity-2020.4.0-py3-none-any.whl.

File metadata

  • Download URL: simplesecurity-2020.4.0-py3-none-any.whl
  • Upload date:
  • Size: 33.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.1.3 CPython/3.9.0 Windows/10

File hashes

Hashes for simplesecurity-2020.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 55947c6b3ebdb59f6c987326c9aebd1987651bdfec68a6eabbdaf2090606ec18
MD5 bc2552322aacd23fb52da0c0ba9dcc89
BLAKE2b-256 ab35f42e55d3abde4199b49dc4479d04894c0378a52eed87b7662c0c56de1229

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page