Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pysa is Meta’s open-source static analyzer for finding security and privacy risks in Python. It uses taint analysis to trace potentially untrusted data from sources to dangerous sinks; it is not a code formatter or a unit-test runner. The project’s current repository says Pysa is distributed with pyre-check and run with pyre analyze after pyrefly check.

What Pysa analyzes

Pysa, short for Python Static Analyzer, checks how data moves through Python code. A source marks data that may be untrusted or sensitive; a sink marks an operation where that data could cause harm or violate a privacy rule. Pysa reports flows between them so a developer can investigate whether the path is unsafe.

Examples include paths that could lead to remote code execution, SQL injection, cross-site scripting (XSS), or privacy-policy violations. The analyzer depends on models that describe sources, sinks, and relevant behavior in the codebase. Those models help Pysa understand application-specific frameworks and data flows.

How to install and run Pysa

  1. Install the pyre-check package with pip in the environment used for the project.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. From the project directory, run pyrefly check. Pysa needs type information, so run this check before analysis.

  3. Run pyre analyze to generate findings.

  4. To explore results, install SAPP with pip install fb-sapp. SAPP can process Pysa output and provides a command-line interface and web UI for investigating findings.

The precise models and configuration needed depend on the project. Meta’s 2020 description said Django and Tornado coverage could work on the first run, while other frameworks generally needed configuration to describe where data enters the server. Treat that as framework guidance from the 2020 account, not a guarantee that every application using those frameworks will be configured correctly without review.

Using Pysa in continuous integration

The official facebook/pysa-action can run Pysa in GitHub Actions. Its documented inputs include the repository directory, a requirements-file path, optional type inference, and default SAPP filters. Findings can be surfaced in GitHub Security code scanning. Set up the action according to its current documentation and check that the project’s dependencies and analysis configuration are available in the CI environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SAPP is useful when a team needs to search and investigate analyzer output rather than read raw results alone. It is a reporting and investigation tool, not the Python analyzer itself.

What Pysa can—and cannot—tell you

Meta described using Pysa on Instagram’s Python codebase, which it characterized in 2020 as millions of lines, as well as on open-source projects. The same account said analysis of a proposed change could return results in about an hour rather than requiring weeks or months of manual review. Those are Meta’s internal operational claims, not independent benchmark results or a guarantee of run time for another codebase.

Pysa is designed to favor catching potential security problems, which means findings need human review. Meta’s 2020 explanation explicitly recognizes both false positives—reported issues that are not actual vulnerabilities—and false negatives—real issues the tool does not report. The source does not publish a numerical precision, recall, or false-positive rate. Teams should therefore treat results as evidence to investigate, not as proof that a finding is exploitable or that unreported code is safe. Models and rules also need continuing refinement as a codebase changes.

Pysa compared with Meta’s other analysis tools

Tool Primary scope Relationship to Pysa
Pysa Security- and privacy-oriented taint analysis for Python The Python analyzer discussed here; distributed with pyre-check.
Infer Static analysis for Java, C++, Objective-C, and C A separate analyzer, not the Python tool named Pysa.
Mariana Trench Android and Java applications A separate analyzer; SAPP can process its output as well as Pysa output.
SAPP Search and investigation of analyzer findings Processes Pysa output and offers CLI and web UI exploration; it is not itself the Python analyzer.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is Pysa the same as Bandit?

No comparison of Pysa and Bandit’s coverage, framework support, type requirements, or reporting behavior is established here, so it would be misleading to declare one a replacement for the other. Pysa’s documented role is Python taint analysis: it traces modeled data flows from sources to sinks and relies on type information. Choose and configure analysis tools according to the checks your project needs; do not assume that any one analyzer catches every security issue.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.