It would be good to run `bandit` as part of the code QA. Right now it fails on our code, but we can try to fix the corresponding issues.