{"repo":"pypa/gh-action-pip-audit","free":true,"listed":false,"github":"https://github.com/pypa/gh-action-pip-audit","clone":"git clone https://github.com/pypa/gh-action-pip-audit.git","description":"A GitHub Action for pip-audit","language":"Python","stars":88,"topics":["github-actions","pip","security","supply-chain"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"gh-action-pip-audit =================== A GitHub Action that uses pip-audit to scan Python dependencies for known vulnerabilities. This project is maintained in part by Trail of Bits with support from Google. This is not an official Google or Trail of Bits product. Index Usage Configuration ⚠️ Internal options ⚠️ Troubleshooting Tips and Tricks Licensing Code of Conduct Usage Simply add pypa/gh-action-pip-audit to one of your workflows: Or, with a virtual environment: By default, pip-audit will run in \" pip list source\" mode, meaning that it'll attempt to collect dependencies from the local environment. See the configuration documentation below for more input and behavioral options. Configuration gh-action-pip-audit takes a variety of configuration inputs, all of which are optional. inputs Default : Empty, indicating \" pip list source\" mode The inputs setting controls what sources pip-audit runs on. To audit one or more requirements-style inputs: To audit a project that uses pyproject.toml for its dependencies: virtual-environment Default : Empty, indicating no virtual environment The virtual-environment setting controls the virtual environment that this action loads to, if specified. The value is the top-level directory for the virtual environment, which is conventionally named env or venv . Depending on your CI and project configuration, you may or may not need this setting. Specifically, you only need it if you satisfy all of the following conditions: 1. You are auditing a","default_branch":null,"files":null,"tree":[],"storefront":"/r/pypa","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/pypa/gh-action-pip-audit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}