-
debian/1.6.2-1
Debian release 1.6.2-1
-
1.4.0
[Important] This release removes the ‘stats’ elements from the JSON output formatter. The same information is available in the metrics section and duplicating the data is noisy and pointless. [Features] - Handle curve keyword arg weak_cryptographic_key [Bug Fixes] - UTF8 encoding fix for skipped filenames - Fixed partial path detection on windows - HTML output now passes markup validation [Behind the Scenes] - Many trivial fixes based on pylint scan - Many cleanups to docs and readme - Added functional tests for B308, B321, and B402
-
1.3.0
[Features] - Add capability to pipe a file into bandit [Bug Fixes] - Fixing B502 and B503 developer docs - Fix for pylint no-self-use error - Don't include openstack/common in flake8 exclude list [Behind the Scenes] - Many trivial fixes based on pylint scan
-
1.2.0
[New Features] - Added "input()" to the list of blacklisted calls (B322) [Bug Fixes] - Tests work with newest GitPython - Blacklist filtering now fixed, B001 no longer needed - Fixed false positive on YAML load() test (B506) - Fix crypto key size issues when we dont know what it is (B505) [Behind the Scenes] - Unit tests now use Mock over MagicMock - Unit tests now use assertEqual correctly - Module imports cleaned up
-
1.1.0
[New Features] - New test for HTTPoxy bug (CVE-2016-5386) - Man page added [Bug Fixes] - XSS bug fixed in HTML output (Security fix) - Various typos and spelling errors fixed [Behind the Scenes] - Catch general exceptions per-file - Docs improvements - Py3.5 bits
-
1.0.1
Re-release of 1.0, CI failed to publish to PyPI
-
1.0
1.0 milestone release [New Features] - Quite a number of new features, please see docs - Test plugins now have IDs - Config is now optional - Config now has a new format, please see docs - Old config compatibility persists but is deprecated now - Config gen tool can create new style configs easily - Test include/exclude (-t/-s) CLI options added - Version '-v' CLI option added - Updated documentation - New test for 'try, except, continue' - Blacklists items now hove IDs for fine control - New plugin interface for blacklist data [Bug fixes] - Several minor fixes - Fixes to try, except, ... tests - Fixes to include/exclude logic [Behind the Scenes] - lots of changes to make config optional - lots of support for old config deprecation - blacklist test completely re-worked
-
0.17.0
Bandit 0.17.0 [New Features] - baseline tool added which runs baseline against previous commit in Git [Behind the Scenes] - status has been moved to stderr - incremental improvements to clean up config - updated README [Documentation] - docs are now automatically generated
-
0.16.2
Bandit 0.16.2 [New Features] - added new config file generating tool [Behind the Scenes] - new functional runtime unit tests added - improved the node visitor code - removed some dead code - simplified baseline matching function
-
0.16.1
Fix for baseline return codes