Hi Jakub, Thanks for raising this bug.
The upstream documentation claims to use /etc/bandit/bandit.yaml, but as you have discovered it is bogus. This is being tracked as an upstream bug[0] and I am working on an upstream fix[1]. Installing the config seemed like the appropriate thing to do as the next upstream release will correctly use the /etc/bandit.yaml file, which should be available in the coming weeks. I think it makes sense to keep this bug open and resolve it with the new upstream version. Thanks! [0] https://bugs.launchpad.net/bandit/+bug/1475510 [1] https://review.openstack.org/#/c/203451/ -- Kind Regards, Dave Walker -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org