{"repo":"pypa/pip-audit","free":true,"listed":false,"github":"https://github.com/pypa/pip-audit","clone":"git clone https://github.com/pypa/pip-audit.git","description":"Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them","language":"Python","stars":1347,"topics":["security","security-audit","python","pip","supply-chain"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"pip-audit ========= pip-audit is a tool for scanning Python environments for packages with known vulnerabilities. It uses the Python Packaging Advisory Database (https://github.com/pypa/advisory-database) via the PyPI JSON API as a source of vulnerability reports. This project is maintained in part by Trail of Bits with support from Google. This is not an official Google or Trail of Bits product. Index Features Installation Third-party packages GitHub Actions pre-commit support Usage Environment variables Exit codes Dry runs Examples Troubleshooting Tips and Tricks Security model Licensing Contributing Code of Conduct Features Support for auditing local environments and requirements-style files Support for multiple vulnerability services (PyPI, OSV) Support for emitting SBOMs in CycloneDX XML or JSON Support for automatically fixing vulnerable dependencies ( --fix ) Human and machine-readable output formats (columnar, Markdown, JSON) Seamlessly reuses your existing local pip caches Installation pip-audit requires Python 3.10 or newer, and can be installed directly via pip : Third-party packages There are multiple third-party packages for pip-audit . The matrices and badges below list some of them: [ ][#conda-forge-package] [ ][#conda-forge-package] [#conda-forge-package]: https://anaconda.org/conda-forge/pip-audit In particular, pip-audit can be installed via conda : Third-party packages are not directly supported by this project. Please consult your package manager's documen","default_branch":null,"files":null,"tree":[],"storefront":"/r/pypa","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/pypa/pip-audit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}