django-commons / django-commons/controls
Investigate utility of Bandit for security static analysis of packages
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 1
- Forks
- 0
- Avg merge
- 18m
- Merged PRs (30d)
- 1
Description
Seth Larson, PSF security developer in residence, recommended that we look into using Bandit, a tool to find common security issues in Python code.
I think there are a few directions we could take this:
- Define a pattern/playbook for maintainers to use in their own project on a periodic basis
- Define a pattern/playbook for Django Commons security team to evaluate the eco-system on a periodic basis
I think this could also be recorded and uploaded to our youtube account.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Bandit documentation and assess how it could support the two proposed security playbook directions. Document a chosen direction, the periodic evaluation process, and whether the work should also be recorded for the Django Commons YouTube account.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100