5f306d7edc
--no-warn-script-location: bandit scripts go to /tmp/.local/bin which is not on PATH, but we invoke via 'python -m bandit' so this is harmless. PIP_DISABLE_PIP_VERSION_CHECK=1: silence the version upgrade notice. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>