Contents

pip-audit 2.7.3

0

A tool for scanning Python environments for known vulnerabilities

A tool for scanning Python environments for known vulnerabilities

Stars: 968, Watchers: 968, Forks: 63, Open Issues: 59

The pypa/pip-audit repo was created 3 years ago and the last code push was 2 days ago.
The project is popular with 968 github stars!

How to Install pip-audit

You can install pip-audit using pip

pip install pip-audit

or add it to a project with poetry

poetry add pip-audit

Package Details

Author
None
License
None
Homepage
None
PyPi:
https://pypi.org/project/pip-audit/
GitHub Repo:
https://github.com/trailofbits/pip-audit

Classifiers

  • Security
No  pip-audit  pypi packages just yet.

Errors

A list of common pip-audit errors.

Code Examples

Here are some pip-audit code examples and snippets.

GitHub Issues

The pip-audit package has 59 open issues on GitHub

  • Make pip-audit's spinner still more responsive
  • Option to skip dependencies with empty PyPI listing.
  • pypi_provider asks for bogus requirement pkg_resources==0.0.0
  • explicitly ignore (e.g. internal) libraries?
  • Remove Python 3.6 support when pip does
  • Make more information available in the reports
  • Feature: output in SARIF format
  • Feature: create GitHub action to simplify GitHub workflow integration
  • Add a –require-hashes flag
  • Support pyproject.toml
  • Support auditing sub-dependencies of individual projects
  • Schematize the PyPI vulnerability API
  • Support other Python packaging formats
  • Integration into pip
  • Support auditing container images

See more issues on GitHub

Related Packages & Articles

pip 24.2

The PyPA recommended tool for installing Python packages.

oletools 0.60.2

Python tools to analyze security characteristics of MS Office and OLE files (also called Structured Storage, Compound File Binary Format or Compound Document File Format), for Malware Analysis and Incident Response #DFIR

mitmproxy 11.0.0

An interactive, SSL/TLS-capable intercepting proxy for HTTP/1, HTTP/2, and WebSockets.