Looks like bandit ignores api directory and checks all code including dependencies. Need to check this. 