Commit Graph

  • b638d96e2e Merge "Adding bandit-baseline tool" Jenkins 2015-12-11 20:25:14 +00:00
  • 00d59dee2c Adding bandit-baseline tool Travis McPeak 2015-12-07 16:47:53 -08:00
  • c9eb2c1321 Merge "Update README with recent changes" Jenkins 2015-12-09 05:31:56 +00:00
  • 9c8d702d27 Fix multiline string with missing space Stanisław Pitucha 2015-12-07 15:31:01 +11:00
  • 9fe19996fe Update README with recent changes Eric Brown 2015-12-04 14:21:43 -08:00
  • bea8509780 Config generator: fix a typo Cyril Roelandt 2015-11-30 13:59:32 +01:00
  • 5079120f31 Merge "Lowering confidence of "any_other_function_with_shell_equals_true"" Jenkins 2015-11-21 00:24:44 +00:00
  • 6d3fc383e2 Merge "bandit-config-generator: Add documentation" Jenkins 2015-11-20 12:25:25 +00:00
  • 72b5e2c1be Merge "Updated from global requirements" 0.16.2 Jenkins 2015-11-19 16:34:54 +00:00
  • d5c526e2ca Updated from global requirements OpenStack Proposal Bot 2015-11-19 15:43:44 +00:00
  • 03e192ba9b bandit-config-generator: Add documentation Cyril Roelandt 2015-11-18 15:30:11 +01:00
  • cb6a04ad36 Lowering confidence of "any_other_function_with_shell_equals_true" Timothy Kelsey 2015-11-19 10:41:27 +00:00
  • 6137fc4876 Simpler baseline matching Timothy Kelsey 2015-11-19 09:02:06 +00:00
  • 0a089e7e3b Merge "Add functional runtime tests" Jenkins 2015-11-18 13:27:47 +00:00
  • fd6cd67712 Merge "Add a configuration generator for bandit" Jenkins 2015-11-18 13:13:46 +00:00
  • 5d96c6f8d4 Merge "Cleaning up node visitor" Jenkins 2015-11-17 17:38:29 +00:00
  • 62fc3546e0 Merge "Improving node visitor" Jenkins 2015-11-17 17:38:16 +00:00
  • 8fa87b6d5f Cleaning up node visitor Timothy Kelsey 2015-11-17 14:55:32 +00:00
  • 123aa4477f Removing unused code Timothy Kelsey 2015-11-17 13:18:32 +00:00
  • 388e6d3f02 Improving node visitor Timothy Kelsey 2015-11-16 14:40:59 +00:00
  • 18bbfcc20e Add a configuration generator for bandit Cyril Roelandt 2015-11-05 15:07:36 +01:00
  • a727880811 Add functional runtime tests Jamie Finnigan 2015-11-13 14:52:04 -08:00
  • 2d96febcfd Fixing a simple issue in results count to fix exit code 0.16.1 Travis McPeak 2015-11-13 19:11:41 +01:00
  • 83d5d843c1 Merge "os.system et al. all spawn a shell so we should use the same logic" 0.16.0 Jenkins 2015-11-13 15:46:14 +00:00
  • 4978c3dc4a Merge "Adding Baseline Capability to the Text Formatter" Jenkins 2015-11-13 10:12:31 +00:00
  • 09a9c28887 Adding baseline capabilities to HTML formatter and update report Travis McPeak 2015-11-12 12:54:33 +01:00
  • a2081f913c Adding Baseline Capability to the Text Formatter Travis McPeak 2015-11-12 12:18:14 +01:00
  • 0e2d3c8e25 Changing the way baseline formatters are indicated Travis McPeak 2015-11-12 11:48:55 +01:00
  • b7256cfcd2 Merge "Changing issue candidates in baseline to ordered dict" Jenkins 2015-11-11 22:39:28 +00:00
  • 5fe2f01e5b Changing issue candidates in baseline to ordered dict Travis McPeak 2015-11-11 18:33:00 +01:00
  • cb08cb03ef os.system et al. all spawn a shell so we should use the same logic Timothy Kelsey 2015-11-11 12:35:40 +00:00
  • a5618ba216 Fixing bug when encountering tuple params Timothy Kelsey 2015-11-11 11:28:58 +00:00
  • 6b19466d9c Merge "Fix simple bug in text formatter excluded files list" Jenkins 2015-11-09 18:25:39 +00:00
  • bca98e95b2 Merge "Improving Bandit Baseline Reporting" Jenkins 2015-11-09 18:20:13 +00:00
  • 6cee1760ac Fix simple bug in text formatter excluded files list Travis McPeak 2015-11-09 17:48:11 +01:00
  • 227cf60428 Improving Bandit Baseline Reporting Travis McPeak 2015-11-06 09:32:19 +01:00
  • b72b5029df blacklist_calls: add Python3 and six versions of some functions Cyril Roelandt 2015-11-06 18:03:16 +01:00
  • 47ddb67cb5 Test for bug 1513091 Stanisław Pitucha 2015-11-05 16:47:51 +11:00
  • 2a328eb786 Fixing bug in injection test 0.15.2 Tim Kelsey 2015-11-04 16:51:12 +00:00
  • 3157f0d67f Merge "Fixing Baseline when a filter is used" 0.15.1 Jenkins 2015-11-04 15:21:11 +00:00
  • 7e93a5fead Merge "Making score sum totals more sane" Jenkins 2015-11-04 15:20:58 +00:00
  • 8333dd4503 Fixing Baseline when a filter is used Travis McPeak 2015-11-02 14:51:51 +01:00
  • a14b91bac1 Fixing Traceback with Bad File Travis McPeak 2015-11-04 08:36:36 +01:00
  • bc94bef649 Making score sum totals more sane Travis McPeak 2015-11-02 20:49:22 +01:00
  • bde5f958be Merge "Added missing HTTP verbs to the requests checks" Jenkins 2015-10-30 08:09:23 +00:00
  • b258d08a7c Added missing HTTP verbs to the requests checks Robert Clark 2015-10-30 14:40:52 +09:00
  • 02f5ae7a7e Remove coverage files after run Timothy Kelsey 2015-10-30 03:22:12 +00:00
  • f571ff0392 Merge "Adding plugin to output in text formatter" 0.15.0 Jenkins 2015-10-23 15:50:28 +00:00
  • 74b0b717db Merge "Adding the plugin name to the HTML report" Jenkins 2015-10-23 15:50:24 +00:00
  • 535fdf618c Merge "Adding missing docs" Jenkins 2015-10-23 15:49:19 +00:00
  • 9e4cc0798e Merge "Changing the confidence in the oslo secret plugin" Jenkins 2015-10-23 14:40:06 +00:00
  • 5cd862738b Merge "Fixing some docs formatting" Jenkins 2015-10-23 12:02:07 +00:00
  • c1518ebe20 Adding missing docs Travis McPeak 2015-10-23 13:00:05 +02:00
  • e52fcefb92 Fixing some docs formatting Timothy Kelsey 2015-10-23 12:00:02 +01:00
  • 70d01d3bc7 Distinguish between formatted and simple commands Stanisław Pitucha 2015-10-23 11:30:08 +11:00
  • 6cc0747126 Changing the confidence in the oslo secret plugin Travis McPeak 2015-10-23 12:48:33 +02:00
  • 3672988bc3 Adding plugin to output in text formatter Travis McPeak 2015-10-23 09:43:14 +02:00
  • cb3627d553 Adding the plugin name to the HTML report Travis McPeak 2015-10-23 09:32:24 +02:00
  • 3acbc1db06 Merge "Ensure each plugin is linked to appropriate sec guidance doc" Jenkins 2015-10-22 15:23:21 +00:00
  • c5c95a1e5c Merge "Adding metrics and CSS styling to HTML formatter" Jenkins 2015-10-22 15:21:52 +00:00
  • 95bce6e38b Merge "This adds baseline filtering to bandit" Jenkins 2015-10-22 15:15:11 +00:00
  • 7a251a8dc6 Adding metrics and CSS styling to HTML formatter Travis McPeak 2015-10-22 11:22:36 +02:00
  • 3200e9dde3 This adds baseline filtering to bandit Timothy Kelsey 2015-10-22 12:09:01 +01:00
  • 9723afb9b8 Ensure each plugin is linked to appropriate sec guidance doc Travis McPeak 2015-10-20 15:22:43 +02:00
  • c9e30bf83b Merge "Add missing documentation for start_process_with_a_shell" Jenkins 2015-10-22 08:37:41 +00:00
  • b3cba501e6 Add missing documentation for start_process_with_a_shell Travis McPeak 2015-10-20 15:40:02 +02:00
  • 5a4732e88c Merge "Collecting metrics code in one place" Jenkins 2015-10-21 14:09:42 +00:00
  • 06b2a6acd4 Collecting metrics code in one place Timothy Kelsey 2015-10-16 13:29:57 +01:00
  • 6e6ab58a59 Merge "Don't create files if we did not ask for them" Jenkins 2015-10-20 20:25:50 +00:00
  • ed9e5bbf8f Don't create files if we did not ask for them Timothy Kelsey 2015-10-20 16:47:25 +01:00
  • c1c59686d6 Merge "Add check for Flask app debug=True usage" Jenkins 2015-10-18 21:24:39 +00:00
  • 18e8f672de Merge "Add doc for weak_cryptographic_key plugin" Jenkins 2015-10-15 17:29:22 +00:00
  • 8ae58916dc Add check for weak elliptic curve keys Eric Brown 2015-10-14 17:51:16 -07:00
  • 9ff442397e Add doc for weak_cryptographic_key plugin Eric Brown 2015-10-14 14:36:21 -07:00
  • aa66e18d95 Adding command line option to exclude paths 0.14.1 Travis McPeak 2015-10-13 16:38:20 +02:00
  • 981ef46a46 Tweaks to #nosec (+ ignore flag, - dead constant) Jamie Finnigan 2015-10-12 16:27:18 -04:00
  • 517ab2f7ab Add check for Flask app debug=True usage Jamie Finnigan 2015-10-12 12:38:27 -04:00
  • 73af54ffcc Merge "Add metrics to text and JSON output formatters" Jenkins 2015-10-13 17:35:51 +00:00
  • 0fe7cc52ca Merge "Add basic metric generation and associated tests" Jenkins 2015-10-13 17:35:46 +00:00
  • cd751263c7 Add metrics to text and JSON output formatters Jamie Finnigan 2015-10-12 14:04:06 -04:00
  • f007ee66b1 Add basic metric generation and associated tests Jamie Finnigan 2015-08-25 15:16:33 -07:00
  • b69ba3df41 Merge "Include context in debug output" Jenkins 2015-10-13 07:16:33 +00:00
  • b6c6563f4a Include context in debug output Jamie Finnigan 2015-10-12 11:01:26 -04:00
  • a3adf07df3 Tidy up plugin list in 'bandit -h' output Jamie Finnigan 2015-10-12 10:30:17 -04:00
  • a0f39927ff Merge "Adding docs for Jinja2 autoescape" 0.14.0 Jenkins 2015-10-12 10:20:34 +00:00
  • b3e334dd7c Adding docs for Jinja2 autoescape Tim Kelsey 2015-10-09 11:13:31 +01:00
  • e90b76698a Merge "Fixing -n behaviour" Jenkins 2015-10-12 00:32:08 +00:00
  • dbc2d27957 Merge "Adding docs for paramiko calls test" Jenkins 2015-10-12 00:29:38 +00:00
  • 37337ec55c Merge "Adding mako template docs" Jenkins 2015-10-09 14:55:41 +00:00
  • a63cf284c0 Adding mako template docs Tim Kelsey 2015-10-09 11:29:06 +01:00
  • 057e63f3ae Check for insecure cipher modes Eric Brown 2015-09-04 13:50:45 -07:00
  • 2a9061560a Merge "Enabling new hardcoded password tests in the config" Jenkins 2015-10-08 16:36:49 +00:00
  • 9a8b0859c1 Merge "Adding docs for subprocess tests" Jenkins 2015-10-08 16:03:39 +00:00
  • 378de82e92 Merge "Bad file permission docs" Jenkins 2015-10-08 16:03:36 +00:00
  • 5850e322ab Merge "Adding Linux wildcard docs" Jenkins 2015-10-08 16:02:41 +00:00
  • 1f6d1c8cd7 Adding docs for subprocess tests Tim Kelsey 2015-10-08 16:17:21 +01:00
  • 016fee281a Adding docs for paramiko calls test Tim Kelsey 2015-10-08 12:24:46 +01:00
  • fac53b146a Adding Linux wildcard docs Tim Kelsey 2015-10-08 11:52:25 +01:00
  • a8275a252d Bad file permission docs Tim Kelsey 2015-10-08 10:40:26 +01:00
  • 7e99e22830 Python 3 compatibility fix Tim Kelsey 2015-10-06 18:25:30 +01:00