fosstars-rating-core icon indicating copy to clipboard operation
fosstars-rating-core copied to clipboard

Bandit scan can be triggered in other ways than GitHub actions

Open sourabhsparkala opened this issue 3 years ago • 0 comments

It is found that Bandit can be triggered in other ways

  • https://github.com/PyCQA/bandit#version-control-integration
  • Existence of .bandit file https://github.com/PyCQA/bandit#per-project-command-line-args
  • Check for more possible configurations as listed above.

Improve on the existing BanditDataProvider

DoD:

  • Complete the above things and integrate them into the current data provider.
  • Duplicate methods may be existing with CodeqlDataProvider refactor to remove redundancies.

sourabhsparkala avatar Jan 17 '22 06:01 sourabhsparkala