Automated security testing built right into your workflow!
You already use flake8 to lint all your code for errors, ensure docstrings are formatted correctly, sort your imports correctly, and much more... so why not ensure you are writing secure code while you're at it? If you already have flake8 installed all it takes is pip install flake8-bandit
.
We use the bandit package from PyCQA for all the security testing.