You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Bandit或其他工具检测跨模块的特定脆弱函数调用?

Answer

Using Bandit to Scan Your Own Dependent Modules

Your custom Bandit test works correctly, but you’re only scanning test.py—which doesn’t contain the direct requests.get call. To catch the usage in more_test.py, you need to include that file (or its parent directory) in your scan command:

bandit test.py more_test/more_test.py

For larger codebases, scan the entire project directory instead of listing individual files:

bandit .

You can also standardize scan targets with a bandit.yaml config file to avoid repeating paths:

exclude_dirs:
  - venv
  - __pycache__
include_files:
  - "*.py"

Run Bandit with the config:

bandit -c bandit.yaml .

Scanning Third-Party/Unmaintained Internal Dependencies

Bandit isn’t optimized for scanning external dependencies (like packages in site-packages), but these tools are better suited for this use case:

1. Semgrep

Semgrep lets you write simple rules to detect function calls across any code, including dependencies. Create a rule file prohibit_requests_get.yaml:

rules:
  - id: prohibit-requests-get
    pattern: requests.get(...)
    message: "Avoid using requests.get"
    severity: ERROR
    languages: [python]

Run it against your code and dependencies (point to your virtual environment’s site-packages if needed):

semgrep --config prohibit_requests_get.yaml . venv/lib/python3.x/site-packages/

2. CodeQL

CodeQL is a powerful static analysis tool that can query for function calls across your entire codebase, including dependencies:

  1. Create a CodeQL database for your project (ensure dependencies are installed in your environment during database creation).
  2. Write a query to find requests.get calls:
import python

from CallExpr call, Attribute attr
where attr.getExpr().hasName("requests") and attr.getAttributeName() = "get" and call.getCallee() = attr
select call, "Use of requests.get detected."
  1. Run the query against your database to retrieve all matching calls.

3. Pyre

Pyre (Facebook’s static analyzer) can detect function usages with custom rules. Define a rule to flag requests.get calls and run it across your code and dependencies to identify vulnerable usages.


内容的提问来源于stack exchange,提问作者Wealot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 05:06:09