Comments (3)
Just had the same issue.
from bandit.
I'm not able to reproduce on macOS. What operating system are you using? What is the value of your TERM environment variable?
Erics-MacBook-Pro-2:examples ericwb$ pre-commit run --all-files
bandit...................................................................Failed
- hook id: bandit
- exit code: 1
[main] INFO profile include tests: None
[main] INFO profile exclude tests: None
[main] INFO cli include tests: None
[main] INFO cli exclude tests: None
[main] INFO running on Python 3.12.2
Run started:2024-03-09 20:40:09.524162
Test results:
>> Issue: [B324:hashlib] Use of weak MD5 hash for security. Consider usedforsecurity=False
Severity: High Confidence: High
CWE: CWE-327 (https://cwe.mitre.org/data/definitions/327.html)
More Info: https://bandit.readthedocs.io/en/0.0.0/plugins/b324_hashlib.html
Location: ./python/stdlib/hashlib_md5.py:4:0
3
4 hashlib.md5()
--------------------------------------------------
>> Issue: [B105:hardcoded_password_string] Possible hardcoded password: 'Don't👏hard👏code👏secrets'
Severity: Low Confidence: Medium
CWE: CWE-259 (https://cwe.mitre.org/data/definitions/259.html)
More Info: https://bandit.readthedocs.io/en/0.0.0/plugins/b105_hardcoded_password_string.html
Location: ./test.py:1:9
1 secret = u'Don\'t👏hard👏code👏secrets'
--------------------------------------------------
Code scanned:
Total lines of code: 12
Total lines skipped (#nosec): 0
Run metrics:
Total issues (by severity):
Undefined: 0
Low: 1
Medium: 0
High: 1
Total issues (by confidence):
Undefined: 0
Low: 0
Medium: 1
High: 1
Files skipped (0):
from bandit.
Hi,
thank you for picking up the issue.
I am using Windows. I am able to reproduce the issue on Powershell 7 (7.4.1), Command Prompt and Git Bash (TERM = xterm-256color).
Issue is occurring both in 1.7.5 and the latest version (1.7.8).
from bandit.
Related Issues (20)
- dependabot.yml should be in .github/workflows
- Add support for `httpx` in `B113` (`request_without_timeout`)
- Issue: [B113:request_without_timeout]
- Flag `markupsafe.Markup` on non-literal content HOT 5
- Mark use of `PKCS1v15` for encryption and decryption a vulnerability HOT 3
- B314 since Python 3.6 is not valid HOT 5
- ssh_no_host_key_verification is failing on Python 3.12
- OSSFuzz Integration HOT 1
- B411 error can't be resolved by the suggested change
- One test fails HOT 1
- Bandit container image.
- # nosec with bandit ID doesn't work properly sometimes HOT 4
- More Info hyperlink is broken HOT 3
- Official GitHub Action
- Can we add a json schema to complete pyproject.toml's [tool.bandit]? HOT 1
- Publish to Test PyPI fails
- assert_used skips change in 1.7.7 HOT 2
- SARIF docs are not rendered HOT 2
- Do performance benchmark testing as part of build
- IndexError: list index out of range while scanning cpython
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from bandit.