Skip to content

Commit

Permalink
Merge pull request #4210 from pypa/feature/update-pyup-info
Browse files Browse the repository at this point in the history
  • Loading branch information
techalchemy authored Apr 28, 2020
2 parents e3c3c59 + 456f3b2 commit 4d93195
Show file tree
Hide file tree
Showing 3 changed files with 12 additions and 10 deletions.
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,9 @@ Pipenv: Python Development Workflow for Humans
[![Azure Pipelines Build Status](https://dev.azure.com/pypa/pipenv/_apis/build/status/Pipenv%20CI?branchName=master)](https://dev.azure.com/pypa/pipenv/_build/latest?definitionId=16&branchName=master)
[![image](https://img.shields.io/pypi/pyversions/pipenv.svg)](https://python.org/pypi/pipenv)


------------------------------------------------------------------------
[[ ~ Dependency Scanning by PyUp.io ~ ]](https://pyup.io)

**Pipenv** is a tool that aims to bring the best of all packaging worlds
(bundler, composer, npm, cargo, yarn, etc.) to the Python world.
Expand Down
19 changes: 9 additions & 10 deletions docs/advanced.rst
Original file line number Diff line number Diff line change
Expand Up @@ -237,16 +237,15 @@ Example::

.. note::

In order to enable this functionality while maintaining its permissive
copyright license, `pipenv` embeds an API client key for the backend
Safety API operated by pyup.io rather than including a full copy of the
CC-BY-NC-SA licensed Safety-DB database. This embedded client key is
shared across all `pipenv check` users, and hence will be subject to
API access throttling based on overall usage rather than individual
client usage.

You can also use your own safety API key by setting the
environment variable ``PIPENV_PYUP_API_KEY``.
Each month, `PyUp.io` updates the ``safety`` database of
insecure Python packages and `makes it available to the
community for free <https://pyup.io/safety/>`__. Pipenv
makes an API call to retrieve those results and use them
each time you run ``pipenv check`` to show you vulnerable
dependencies.

For more up-to-date vulnerability data, you may also use your own safety
API key by setting the environment variable ``PIPENV_PYUP_API_KEY``.


☤ Community Integrations
Expand Down
1 change: 1 addition & 0 deletions news/4210.trivial.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Updated PyUp.io information to reflect current situation.

0 comments on commit 4d93195

Please sign in to comment.