Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Bandit is a tool designed to find common security issues in Python code.

PyCQA/bandit có thân thiện với người mới không?

Gần đây có quá ít pull request của người đóng góp bên ngoài gửi tới PyCQA/bandit để nói chúng được merge thường xuyên đến đâu. Hiện có 5 issue phù hợp với người mới đang mở.

Star
8.3k
Fork
836
Issue cho người mới đang mở
5
Issue đã lập chỉ mục
194
Merge trung bình
3 giờ 51 phút
Pull request đã merge (30 ngày)
2
Ngôn ngữ chính
Python
Giấy phép
Apache-2.0
Lần push lên GitHub gần nhất
29/8/2026
Lập chỉ mục gần nhất
19/9/2026
Hướng dẫn đóng góp
Hướng dẫn đóng góp
Quy tắc ứng xử
Quy tắc ứng xử
Label cho người mới
good first issue

Cách đóng góp cho PyCQA/bandit

  1. Hãy đọc hướng dẫn đóng góp trước: nó cho biết maintainer muốn thay đổi được đề xuất, kiểm thử và review ra sao.
  2. Hãy đọc quy tắc ứng xử: nó áp dụng cho issue và pull request cũng như trò chuyện.
  3. Đóng góp của bạn sẽ được phát hành theo giấy phép Apache-2.0 của dự án.
  4. Chọn một trong 5 issue phù hợp với người mới đang mở bên dưới và bình luận rằng bạn muốn làm nó trước khi bắt đầu.

Các issue có thể đã có người làm được xếp cuối danh sách. Sắp xếp tất cả theo ngày

  • Man page disagrees with the current CLI options and defaults
    Đang mở

    Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 88/100

    PyCQA/bandit#1474 · 1 bình luận ·

  • Test issue
    Đang mở

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 1/100

    PyCQA/bandit#1468 ·

  • Baseline matching ignores line number and uses set membership, not count
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 75/100

    PyCQA/bandit#1467 · 1 bình luận ·

  • B501 and B113 skip requests.request(), while httpx.request() is checked
    Đang mở

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100

    PyCQA/bandit#1465 · 1 bình luận ·

  • Troubles with conflicting cryptography and cffi
    Đang mở
    bug

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 42/100

    PyCQA/bandit#1461 · 3 bình luận ·

  • Feature request: Adding Canary Credentials to detect supply chain compromise
    Đang mở
    enhancement

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100

    PyCQA/bandit#1432 ·

  • `bandit -ii -ll -ii -ll` raises an `IndexError`
    Đang mở
    bug

    Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100

    PyCQA/bandit#1423 · 1 bình luận ·

  • B704 false negative for local Markup subclasses (CVE-2025-54384)
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100

    PyCQA/bandit#1405 · 2 bình luận ·

  • B701: Extend Jinja2 checks to cover dynamic template source execution
    Đang mở
    enhancement

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 56/100

    PyCQA/bandit#1404 · 3 bình luận · 3 reaction ·

  • Proposal: Detecting Flask file-serving API misuse
    Đang mở
    enhancement

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 67/100

    PyCQA/bandit#1403 · 1 bình luận · 3 reaction ·

  • Feature request (with my own implementation): add a plugin which detects common SSRF cases where user-controlled URLs flow into outbound HTTP requests
    Đang mở
    enhancement

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100

    PyCQA/bandit#1401 · 2 reaction ·

  • Methods to Bypass Bandit Detection
    Đang mở
    bug

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100

    PyCQA/bandit#1399 · 2 bình luận ·

  • False negative: narrow argument-shape checks in B508/B509
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100

    PyCQA/bandit#1397 · 2 bình luận ·

  • False negative: B104 misses `bind(("", port))` wildcard host
    Đang mở
    bug

    Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100

    PyCQA/bandit#1395 · 1 bình luận ·

  • False negative: B501 misses `verify=False` on `requests.Session` / `httpx.Client` instance methods
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100

    PyCQA/bandit#1394 ·

  • False negative: B202 unsafe `tarfile.extract()` not detected
    Đang mở
    bug

    Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100

    PyCQA/bandit#1392 ·

  • False negative: B103 fails to detect dangerous permissions set via stat module constants
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100

    PyCQA/bandit#1390 ·

  • False Negatives in B105/B106/B107 Hardcoded Password Detection
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 62/100

    PyCQA/bandit#1383 · 1 bình luận ·

  • Follow-up on GHSA-ggq6-wv5j-cpfg
    Đang mở
    bug

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100

    PyCQA/bandit#1381 ·

  • Unclear FAQ entry regarding "Under Which Version of Python Should I Install Bandit?"
    Đang mở
    enhancement

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100

    PyCQA/bandit#1375 ·

  • [Security] tarfile.extractall without member validation in examples/tarfile_extractall.py
    Đang mở

    Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100

    PyCQA/bandit#1373 · 1 bình luận ·

  • Flag logging/printing of likely sensitive information
    Đang mở
    enhancement

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100

    PyCQA/bandit#1371 ·

  • Suppressing B105 on a multiline dict assignment
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 42/100

    PyCQA/bandit#1352 · 1 bình luận ·

  • using `xml.etree.ElementTree.fromstring` shouldn't raise errors in python versions 3.11 and up
    Đang mở
    bug

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100

    PyCQA/bandit#1344 ·

  • Add check for decompression bomb vulnerabilities
    Đang mở
    enhancement

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100

    PyCQA/bandit#1339 · 1 bình luận ·

  • Should exit with non-zero code when scanning fails
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100

    PyCQA/bandit#1326 · 1 reaction ·

  • Add support for per-file rule ignores in configuration
    Đang mở
    enhancement

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100

    PyCQA/bandit#1322 · 1 bình luận · 4 reaction ·

  • Add Installation Guidelines in README.md
    Đang mở
    bug

    Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 55/100

    PyCQA/bandit#1320 · 4 bình luận ·

  • Sarif formatter physicalLocation calculation error
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 72/100

    PyCQA/bandit#1311 · 1 bình luận · 1 reaction ·

  • Broken JUnit-like XML report files
    Đang mở
    bug

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100

    PyCQA/bandit#1304 ·

  • not distinguishing sql statement with mixed stringbased query construction and sanitised parameterised sql query
    Đang mở
    bug

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100

    PyCQA/bandit#1302 ·

  • Add report formatter for Github Actions annotations
    Đang mở
    enhancement

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100

    PyCQA/bandit#1301 · 7 bình luận ·

  • B614 False Positive when using torch.jit.load
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100

    PyCQA/bandit#1293 ·

  • bandit version and documentation reference in pre-commit run
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 42/100

    PyCQA/bandit#1280 · 2 bình luận ·

  • Allow customising colours
    Đang mở
    enhancement

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100

    PyCQA/bandit#1271 · 4 bình luận · 5 reaction ·

  • pysnmp under new ownership with breaking compatilbility
    Đang mở
    bug

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100

    PyCQA/bandit#1264 · 1 bình luận ·

  • Consider using argparse-manpage to build the man page from argparse
    Đang mở
    enhancement

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 42/100

    PyCQA/bandit#1256 ·

  • Pre-commit hook unable to encode non ascii characters
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100

    PyCQA/bandit#1251 ·

  • bug(standard_streams): console messages with the prefix “[main] INFO” if the configuration file in the INI format
    Đang mở

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100

    PyCQA/bandit#1250 ·

  • feature_request(verbose): “--verbose” command-line argument without the “Files excluded” section
    Đang mở

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100

    PyCQA/bandit#1249 ·

  • blacklist cloudpickle in pickle blacklist
    Đang mở
    enhancement

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100

    PyCQA/bandit#1236 ·

  • Support AI powered suggestion of fixes
    Đang mở
    enhancement

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100

    PyCQA/bandit#1214 · 2 bình luận · 1 reaction ·

  • #nosec BXXX does not contribute to `Total lines skipped (#nosec)`
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100

    PyCQA/bandit#1205 · 1 bình luận ·

  • f-strings marked with a `# nosec BXXX` show an incorrect warning about no failed tests appears
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100

    PyCQA/bandit#1204 · 4 bình luận · 1 reaction ·

  • pre-commit hook can't read version --> wrong URL generated
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100

    PyCQA/bandit#1202 · 4 bình luận ·

  • Expand `B404, B602, B603 and B604` to include anyio calls
    Đang mở
    enhancement

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100

    PyCQA/bandit#1199 · 1 reaction ·

  • Create a control flow graph to traverse code in possible execution order
    Đang mở
    enhancement

    Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100

    PyCQA/bandit#1197 · 2 bình luận · 1 reaction ·

  • Bandit Skipping Directory and Unable to Output Report Error
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100

    PyCQA/bandit#1190 · 1 bình luận ·

  • Add a custom plugin from configuration instead of setuptools
    Đang mở
    enhancement

    Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100

    PyCQA/bandit#1188 · 1 reaction ·

  • bandit does not consistently detect extractall with TarFile
    Đang mở
    bug

    Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100

    PyCQA/bandit#1171 · 1 bình luận ·

Đang hiển thị 100 mục mới nhất

Trang này chỉ liệt kê những gì được lập chỉ mục gần đây. Bộ lọc nâng cao có toàn bộ kho, thu hẹp theo ngôn ngữ, độ khó và thời lượng.

Mở bộ lọc nâng cao

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.