Bandit: Automated Python Code Security Linter
Bandit is a tool designed to find common security issues in Python code.
At a glance
- What is it?
- A tool for finding common security issues in Python code through static analysis. Scans for hardcoded passwords, insecure cryptography, SQL injection vulnerabilities, and other dangerous patterns.
- Who is it for?
- Bandit is for Python developers who want automated security scanning in their CI/CD pipeline. Adopt it if you need basic security issue detection and want a tool that integrates with linting workflows.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 9 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
Detecting Hardcoded Secrets and Injection Vulnerabilities
Bandit finds common security issues in Python code through static analysis. The README documents that Bandit processes each file, builds an Abstract Syntax Tree (AST) from it, and runs appropriate plugins against the AST nodes. Once scanning is complete, Bandit generates a report with findings. Common problems detected include hardcoded credentials in source code, insecure use of cryptography libraries, SQL injection vulnerabilities, command injection risks, unsafe deserialization with pickle, unsafe file operations, and dangerous function calls. Bandit automates the detection of these patterns, catching issues before code review or deployment. The tool was originally developed within the OpenStack Security Project and later moved to PyCQA. This is for teams that want security scanning as part of their development workflow, integrated into CI/CD pipelines to prevent vulnerable code from reaching production. The tool requires Python 3.10 or later, according to setup.py.
Installation and Running Bandit
Bandit is installed via pip, where it pulls dependencies: PyYAML for configuration, stevedore for plugin loading, colorama for Windows terminal colors, and rich for formatted output. You run Bandit on your Python codebase, specifying the directory or files to scan. It scans the code and outputs a report of security issues with line numbers, severity levels, and recommendations for fixing each issue. Configuration options let you specify which rules to check, exclude certain files or directories, or run only specific rules. You can skip rules on a per-file basis by adding comments to your code. Results can be exported in multiple formats including JSON, CSV, and plain text for integration with other tools and CI/CD systems. Bandit is also available as a Docker container image built and hosted on ghcr.io, with pre-built images for amd64, arm64, armv7, and armv8 architectures. Container images are signed with sigstore cosign, letting you verify authenticity before use. The project includes a .pre-commit-hooks.yaml file for pre-commit integration, and tox.ini for running tests across multiple Python versions. This makes Bandit straightforward to integrate into existing development workflows.
Pre-Commit Hooks and CI/CD Integration
Bandit integrates into development workflows. It can run as a pre-commit hook to catch issues before code is committed. It integrates with CI/CD pipelines like GitHub Actions, GitLab CI, and Jenkins. The tool's configurable output formats allow parsing results into other systems. Severity levels help prioritize security work: HIGH issues should be fixed immediately, MEDIUM issues should be addressed soon, LOW issues can be deferred. Developers can suppress specific warnings with comments when they've reviewed the code and determined it's safe. The README documents integration patterns and examples.
Detecting Hardcoded Secrets, Weak Crypto, and Injection Risks
Bandit includes rules for common security problems. It detects hardcoded passwords, API keys, and database credentials that appear in source code. It identifies use of weak hash functions like MD5 and SHA1 when stronger alternatives are available. It flags dangerous pickle usage for deserialization, which can execute arbitrary code. SQL injection risks are detected when user input reaches database queries without proper parameterization. Command injection and code injection patterns are identified. Unsafe file permissions, insecure random number generation, and other issues are caught. Each rule can be configured or disabled based on your security requirements. The README lists the available rules, their severity, and what they check for. Rules are documented so developers understand why an issue was flagged. The repository includes an examples/ directory with Python files demonstrating vulnerable patterns, such as examples/assert.py, examples/hardcoded-passwords.py, examples/eval.py, examples/exec.py, examples/django_sql_injection_raw.py, and examples/crypto-md5.py, so developers can see what Bandit detects. The tool can scan and report on all of these patterns.
Configuring Rules and Output Formats
Bandit can be configured with allow-lists and deny-lists for specific rules. A configuration file specifies which rules to enable, exclude, or skip. Severity levels (LOW, MEDIUM, HIGH) help prioritize issues, so your team knows which vulnerabilities to address first. The tool supports output in multiple formats: text, JSON, CSV, and others for integration with CI/CD systems and security dashboards. Bandit integrates into linting workflows with tools like pre-commit through the .pre-commit-hooks.yaml file, letting you run security checks automatically before code is committed. The tool can be invoked from the command line, integrated into test suites via tox, or run as a GitHub Action in CI/CD pipelines. Rules are composable and can be combined with other PyCQA tools like flake8, pylint, or isort for comprehensive code quality checking.
Static Analysis Cannot Detect Runtime Issues
Bandit is a static analysis tool: it reads code without executing it. This means it cannot detect runtime security issues, logic flaws, or vulnerabilities that only manifest during execution. Bandit uses pattern matching and rule-based heuristics, so it may miss sophisticated attacks or novel vulnerability patterns. False positives are possible: the tool may flag code as insecure when it's actually safe. False negatives are also possible: some real vulnerabilities may not be detected. Bandit should not be the only security tool in your pipeline. Manual code review by security professionals is still necessary. For comprehensive security analysis, Bandit is best used alongside dynamic analysis tools, penetration testing, and security audits. The tool has no official documentation of detection accuracy or false positive rates, so you should test Bandit on your codebase to understand its effectiveness for your specific security concerns. Many open-source projects use Bandit in CI/CD as a first-pass screen but pair it with additional security practices.
Part of PyCQA: Apache 2.0 Licensed and Actively Maintained
Bandit is part of PyCQA (Python Code Quality Authority), an established open-source organization focused on Python quality tools. The last push was 2026-09-21, showing active maintenance. The project is licensed under Apache 2.0. Bandit is widely used in Python projects for security linting in enterprise and open-source codebases. The tool is developed openly and accepts contributions from the community.
Editorial conclusion
Bandit is for Python developers who want automated security scanning in their CI/CD pipeline. Adopt it if you need basic security issue detection and want a tool that integrates with linting workflows. The tool is part of PyCQA, an established quality assurance community. Skip it if your security needs require deep manual analysis or if you need runtime security monitoring. Verify that Bandit's built-in rules cover the issues you care about before relying on it as your sole security tool.
Frequently asked questions
What is Bandit?
Bandit is a security linting tool for Python. It scans code for common security issues like hardcoded secrets, insecure cryptography, and injection vulnerabilities.
How do I use Bandit?
Install via pip, then run `bandit -r your_project/` on your Python code. Bandit analyzes the code and reports security issues with severity levels and line numbers.
Can I configure Bandit rules?
Yes. Bandit rules can be configured, disabled, or customized. The tool supports allow-lists and deny-lists for specific checks.
Can Bandit integrate with CI/CD?
Yes. Bandit outputs results in multiple formats (JSON, CSV) for integration with CI/CD pipelines. It can be used with pre-commit hooks.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/pycqa-bandit)