如何用Bandit或其他工具检测跨模块的特定脆弱函数调用?
Using Bandit to Scan Your Own Dependent Modules
Your custom Bandit test works correctly, but you’re only scanning test.py—which doesn’t contain the direct requests.get call. To catch the usage in more_test.py, you need to include that file (or its parent directory) in your scan command:
bandit test.py more_test/more_test.py
For larger codebases, scan the entire project directory instead of listing individual files:
bandit .
You can also standardize scan targets with a bandit.yaml config file to avoid repeating paths:
exclude_dirs: - venv - __pycache__ include_files: - "*.py"
Run Bandit with the config:
bandit -c bandit.yaml .
Scanning Third-Party/Unmaintained Internal Dependencies
Bandit isn’t optimized for scanning external dependencies (like packages in site-packages), but these tools are better suited for this use case:
1. Semgrep
Semgrep lets you write simple rules to detect function calls across any code, including dependencies. Create a rule file prohibit_requests_get.yaml:
rules: - id: prohibit-requests-get pattern: requests.get(...) message: "Avoid using requests.get" severity: ERROR languages: [python]
Run it against your code and dependencies (point to your virtual environment’s site-packages if needed):
semgrep --config prohibit_requests_get.yaml . venv/lib/python3.x/site-packages/
2. CodeQL
CodeQL is a powerful static analysis tool that can query for function calls across your entire codebase, including dependencies:
- Create a CodeQL database for your project (ensure dependencies are installed in your environment during database creation).
- Write a query to find
requests.getcalls:
import python from CallExpr call, Attribute attr where attr.getExpr().hasName("requests") and attr.getAttributeName() = "get" and call.getCallee() = attr select call, "Use of requests.get detected."
- Run the query against your database to retrieve all matching calls.
3. Pyre
Pyre (Facebook’s static analyzer) can detect function usages with custom rules. Define a rule to flag requests.get calls and run it across your code and dependencies to identify vulnerable usages.
内容的提问来源于stack exchange,提问作者Wealot

