bandit-sarif-formatter
A Bandit formatter for the Static Analysis Results Interchange Format (SARIF) Version 2.1.0 file format.
Decision gist · record as of 2026-08-14
No. The package is abandoned and has not been updated since 2019-10-05. While it has no known vulnerabilities and low install friction, the lack of maintenance means it will not be compatible with current or future versions of Bandit or Python. Verify first that this formatter works with your current Bandit version before installing.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Bandit to be installed separately; the formatter is a plugin that extends Bandit's output capabilities.
- Low install friction with just two runtime dependencies.
- However, the package is abandoned—last release was 2019-10-05 and the repository was archived.
License · maintenance · safety
MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions. You may use this in proprietary projects without sharing source code, though you must retain the license notice.
last release 2019-10-05 (2505 days) · last repo commit 2023-09-19 · 20 stars · archived
0 known vulnerabilities (OSV.dev, 2026-08-14) · 155,954 downloads/mo, #10,796 on PyPI
Alternatives
Verify before relying
pip install bandit-sarif-formatter
bandit --format sarif [targets] --output out.sarif- Whether this formatter remains compatible with current Bandit versions, given the package has not been updated since 2019-10-05.
- Whether jschema-to-python and sarif-om dependencies have received security updates or breaking changes since the formatter's last release.
- Whether Bandit itself now offers native SARIF support, making this formatter redundant.
What it is and what it does
bandit-sarif-formatter is a report formatter plugin for Bandit, Python's security analyzer. It takes Bandit's security findings and outputs them in SARIF (Static Analysis Results Interchange Format) Version 2.1.0, a standardized format maintained by OASIS for security and code-analysis tools. This allows Bandit results to be consumed by CI/CD pipelines, security dashboards, and other tools that understand SARIF.
The package depends on jschema-to-python and sarif-om to handle schema validation and SARIF object modeling. It is invoked as a command-line flag to Bandit and produces a JSON file containing the analysis results in standard format. However, the package has been abandoned since its initial release and may not work reliably with recent versions of Bandit or Python.
Use it for
- Export Bandit security findings to a standardized format for ingestion into enterprise security dashboards or SIEM systems.
- Integrate Bandit results into CI/CD pipelines that expect SARIF input from multiple static analysis tools.
- Archive security scan results in a vendor-neutral format for compliance reporting and historical analysis.
- Feed Bandit output to third-party tools that parse SARIF to correlate findings across multiple security scanners.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is abandoned and has not been updated since 2019-10-05. While it has no known vulnerabilities and low install friction, the lack of maintenance means it will not be compatible with current or future versions of Bandit or Python. Verify first that this formatter works with your current Bandit version before installing.
Install
bandit-sarif-formatter on PyPI
Before you install
Low install friction with just two runtime dependencies. However, the package is abandoned—last release was 2019-10-05 and the repository was archived. No updates have been made since the initial release, so it will not receive bug fixes or compatibility updates.
Requires Bandit to be installed separately; the formatter is a plugin that extends Bandit's output capabilities.
License in practice
MIT license permits free use, modification, and distribution with minimal restrictions. You may use this in proprietary projects without sharing source code, though you must retain the license notice.
Quickstart
pip install bandit-sarif-formatter
bandit --format sarif [targets] --output out.sarif
Verify before relying
- Whether this formatter remains compatible with current Bandit versions, given the package has not been updated since 2019-10-05.
- Whether jschema-to-python and sarif-om dependencies have received security updates or breaking changes since the formatter's last release.
- Whether Bandit itself now offers native SARIF support, making this formatter redundant.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >= 2.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesjschema-to-pythonsarif-om |
| Maintenance | Abandoned 2,505 days since the last release |
| Last repo commit | repository archived |
| First released | |
| Downloads | 155,954 / month, #10,796 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python |
Evidence: bandit_sarif_formatter-1.1.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “bandit sarif formatter”
- bandit-sarif-formatterConverts Bandit security analysis output into SARIF 2.1.0 format for…
- flake8-banditIntegrates bandit security checks into flake8 linting, reporting…
- mabwiserMABWiser implements multi-armed bandit algorithms for decision-making…
Give your agent the search over MCP, or paste the wish link into any chat.
More Quality Assurance packages
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.
Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.
Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.
pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.
Install it if your test suite takes long enough that parallelization would save meaningful time.
Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.
Install it if you work with CloudFormation templates.
See also sarif-om · sarif-tools · bandit · flake8-bandit · readme-renderer · logging-formatter-anticrlf · py-deviceid · django-log-formatter-asim · junit-xml-2 · reuters-style