Suggest a tool

Bandit

Metrics as of , from the GitHub or GitLab API of each repository. Refreshed monthly.

What Bandit is

Bandit is a security linter for Python code maintained by PyCQA. It looks for common security issues by parsing each file into an abstract syntax tree. Plugins then run against the AST nodes. After scanning all files, Bandit produces a report. The project began in the OpenStack Security Project before moving to PyCQA. A container image is published on ghcr.io for amd64, arm64, armv7 and armv8. Each image is signed with sigstore cosign.

Written from the project's README, read .

Category
Security testing, Code quality and static analysis
License
Apache-2.0
Language
Python
Changelog
Releases on GitHub

Repository metrics

Repository metrics
Stars8,2781
Forks8371
Open issues and PRs2581
Contributors1971
Commits in the last 90 days91
Last commit2026-09-211
Last release1.9.4, 2026-02-251
Fetched

1 Fetched from the GitHub or GitLab API on . Hover a value for its own date.

Status

activeLast commit within 90 days of the fetch date.

Computed from the last commit date and the archive flag on the fetch date. See the status rules.

Alternatives

Listed security testing tools, same primary language first, then by GitHub stars. Each line gives one fact from the tool's documentation where it differs from Bandit's, with its source.

How to install

docker pull ghcr.io/pycqa/bandit/bandit
From README, read .

Questions

Is Bandit open source?

Yes. Bandit is released under Apache-2.0, an OSI-approved license, as reported by the GitHub API on 2026-09-22.

Is Bandit maintained?

On 2026-09-22, the last commit to the default branch was on 2026-09-21, so the listed status is active. Rule: Last commit within 90 days of the fetch date.

How many GitHub stars does Bandit have?

8,278 stars on 2026-09-22, from the GitHub API. The number is refreshed at each monthly update.

What language is Bandit written in?

The repository's primary language, as reported by the GitHub API, is Python.

How do I install Bandit?

The README gives this command: docker pull ghcr.io/pycqa/bandit/bandit

Sources

  1. GitHub REST API: repository, read
  2. GitHub REST API: commits, read
  3. GitHub REST API: latest release, read
  4. GitHub REST API: contributors, read
  5. README, read