Assemble semgrep bandit ruleset with 100% coverage w.r.t. original bandit analyzer (baseline)
The Gap analysis: bandit rule coverage for semgrep revealed that ~47% of the rules from bandit (our baseline) are not not covered or incompletely covered by the semgrep bandit ruleset (State: 2021/02/03).
While we worked on the gap analysis, we closed them as we went through the bandit rules so that we have all the data we need to assemble new bandit ruleset for semgrep with 100% coverage (w.r.t. to our baseline) by combining the semgrep bandit ruleset, bandit-closed-gaps.yaml and https://github.com/returntocorp/semgrep-rules.