django-commons / django-commons/controls

Investigate utility of Bandit for security static analysis of packages

Open
#83 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question security
Dominant language
No language data
Stars
1
Forks
0
Avg merge
18m
Merged PRs (30d)
1

Description

Seth Larson, PSF security developer in residence, recommended that we look into using Bandit, a tool to find common security issues in Python code.

I think there are a few directions we could take this:

  1. Define a pattern/playbook for maintainers to use in their own project on a periodic basis
  2. Define a pattern/playbook for Django Commons security team to evaluate the eco-system on a periodic basis

I think this could also be recorded and uploaded to our youtube account.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Bandit documentation and assess how it could support the two proposed security playbook directions. Document a chosen direction, the periodic evaluation process, and whether the work should also be recorded for the Django Commons YouTube account.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.