Review results of bandit on master

now that there is a sast job in ci, at least the high risk items should be reviewed: https://gitlab.com/BuildStream/buildstream/security/dashboard/?project_id=1975139&scope=dismissed&page=1&days=90