NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #675 most downloaded on PyPI
Security oriented static analyser for python code.
Last release 7 months ago
25 Feb 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 47 of 49 stable releases
1 version withdrawn
withdrawn after publishing
12 years old
50 releases · first in 2015
chore: fixed some typos in comments by @jakob1379 in #1351
Full Changelog: 1.9.3...1.9.4
One column per quarter.
Bump actions/checkout from 5 to 6 by @dependabot [bot] in #1334
VALUES( without space by @kfess in #1337Full Changelog: 1.9.2...1.9.3
Argparse Python 3.14 enhancements by @ericwb in #1331
Full Changelog: 1.9.1...1.9.2
More Python version related fixes by @ericwb in #1327
Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 by @dependabot in #1279
Full Changelog: 1.8.5...1.8.6
Fix the rendering of the CI/CD doc by @ericwb in #1274
Full Changelog: 1.8.4...1.8.5
Bump docker/build-push-action from 6.10.0 to 6.11.0 by @dependabot in #1220
Full Changelog: 1.8.2...1.8.3
Revert "Start testing with 3.14 alphas" by @ericwb in #1217
Full Changelog: 1.8.1...1.8.2
Bump docker/build-push-action from 6.9.0 to 6.10.0 by @dependabot in https://github.com/PyCQA/bandit/pull/1209
Full Changelog: https://github.com/PyCQA/bandit/compare/1.8.0...1.8.1
Bump docker/build-push-action from 6.7.0 to 6.9.0 by @dependabot in https://github.com/PyCQA/bandit/pull/1178
Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.10...1.8.0
Bump docker/build-push-action from 5.4.0 to 6.0.0 by @dependabot in https://github.com/PyCQA/bandit/pull/1147
httpx in B113 by @mkniewallner in https://github.com/PyCQA/bandit/pull/1060Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.9...1.7.10
Bump docker/build-push-action from 5.1.0 to 5.2.0 by @dependabot in https://github.com/PyCQA/bandit/pull/1117
configfile in .bandit file by @bersbersbers in https://github.com/PyCQA/bandit/pull/1052Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.8...1.7.9
[B605] Add functions that are vulnerable to shell injection. by @shihai1991 in https://github.com/PyCQA/bandit/pull/1116
Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.7...1.7.8
Add the new release to bandit versions of bug template by @ericwb in https://github.com/PyCQA/bandit/pull/1075
Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.6...1.7.7
Avoid gitpyhon CVE-2022-24439 by @carlosduelo in https://github.com/PyCQA/bandit/pull/1048
pip install commands in the pythonpackage.yml workflow by @mportesdev in https://github.com/PyCQA/bandit/pull/1021random.Random to B311 checks by @shiftinv in https://github.com/PyCQA/bandit/pull/940wrap_file_object by @mportesdev in https://github.com/PyCQA/bandit/pull/1037RawSQL by @kevinmarsh in https://github.com/PyCQA/bandit/pull/765importlib-metadata fallback by @mkniewallner in https://github.com/PyCQA/bandit/pull/1066Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.5...1.7.6
Check for deprecated TLS 1.1 by @ericwb in https://github.com/PyCQA/bandit/pull/928
toml with tomli by @mkniewallner in https://github.com/PyCQA/bandit/pull/829%s placeholders. by @mportesdev in https://github.com/PyCQA/bandit/pull/934exclude_dirs option available in TOML and YAML by @bittner in https://github.com/PyCQA/bandit/pull/876project_urls by @KOLANICH in https://github.com/PyCQA/bandit/pull/985Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.4...1.7.5
Fix traceback in hashlib_insecure_functions by @ericwb in https://github.com/PyCQA/bandit/pull/834
Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.3...1.7.4
Rely on toml conditionally by @sigmavirus24 in https://github.com/PyCQA/bandit/pull/780
Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.2...1.7.3
Fix broken reported URL link for B107 by @bagerard in https://github.com/PyCQA/bandit/pull/751
setup.cfg by @mkniewallner in https://github.com/PyCQA/bandit/pull/755Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.1...1.7.2
Specify output_file encoding as utf-8 by @Brcrwilliams in https://github.com/PyCQA/bandit/pull/364
Full Changelog: https://github.com/PyCQA/bandit/compare/1.7.0...1.7.1
Use GitHub Action badge for build by @ericwb in https://github.com/PyCQA/bandit/pull/651
Full Changelog: https://github.com/PyCQA/bandit/compare/1.6.3...1.7.0
Replace setattr by @tylerwince in https://github.com/PyCQA/bandit/pull/493
Full Changelog: https://github.com/PyCQA/bandit/compare/1.6.2...1.6.3
Performance fix by @tylerwince in https://github.com/PyCQA/bandit/pull/502
Full Changelog: https://github.com/PyCQA/bandit/compare/1.6.1...1.6.2
add namespaces for parent attributes by @tylerwince in https://github.com/PyCQA/bandit/pull/492
Full Changelog: https://github.com/PyCQA/bandit/compare/1.6.0...1.6.1
Fix DeprecationWarning: invalid escape sequence by @BoboTiG in https://github.com/PyCQA/bandit/pull/441
Full Changelog: https://github.com/PyCQA/bandit/compare/1.5.1...1.6.0
Fixed crash on dynamic import traversal by @evqna in https://github.com/PyCQA/bandit/pull/369
Full Changelog: https://github.com/PyCQA/bandit/compare/1.5.0...1.5.1
Travis ci file by @lukehinds in https://github.com/PyCQA/bandit/pull/282
Full Changelog: https://github.com/PyCQA/bandit/compare/1.4.0...1.5.0
Fixing some UTF8 encoding issues in file names
Fixing B502 and B503 developer docs
Updated from global requirements
Add check for httpoxy vulnerability
Adding accurate docs for new bandit config
Nothing published for this version
Nothing published for this version
Use sphinx autodoc to generate docs from docstring
Updated from global requirements
Fixing a simple issue in results count to fix exit code
Adding baseline capabilities to HTML formatter and update report
* Fixing bug in injection test
Fixing Baseline when a filter is used
Distinguish between formatted and simple commands
Adding command line option to exclude paths
Adding docs for Jinja2 autoescape
Find bandit.yaml when in virtualenv
Add other known weak MD hash modules
Actually default to /etc/ rather than just claim
Address multiline node lineno inaccuracies
Changing config file search paths
Fixing info output that was breaking JSON format
Fix vulnerability aggregation bug
Your coding agent can read these notes before it upgrades. Set up the MCP server →