-
Notifications
You must be signed in to change notification settings - Fork 65
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Build a simple standalone audit tool #1
Comments
👋 First of all, I'm super excited about the work/features discussed in pypi/warehouse#9407. I really hope with all those major players involved this gets the attention that it deserves. Thank you! :) Regarding this issue. I wrote a little tool a while ago called
The only difference between the |
Hey, that looks awesome. Thanks for reaching out and letting us know about this one! I wonder if we might be able to reuse part or all of what you have to build a more officially supported |
This is effectively done with the current release of https://pypi.org/project/pip-audit/, which is still under development. I'll close this issue in favor of more detailed issues at https://github.com/trailofbits/pip-audit/issues. |
Build a simple standalone audit tool which just queries https://osv.dev with the list of installed packages.
Once pypi/warehouse#9407 is merged and vulnerabilities are returned in the simple JSON API, we can switch that that instead.
The text was updated successfully, but these errors were encountered: