pkg.soopen package index

brew / rank 3173

Install pip-audit with Homebrew, Nix

Audits Python environments and dependency trees for known vulnerabilities. Version 2.10.1 via Homebrew; verified 2026-09-11. Also installable with nix: nix profile install nixpkgs#pip-audit.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install pip-audit

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#pip-audit

nixpkgs package indexes · pkgs/by-name/pi/pip-audit/package.nix · source: api.github.com

overview

Package summary

Audits Python environments and dependency trees for known vulnerabilities

Commands and aliases

  • pip-audit

history

Project history and usage

pip-audit is a PyPA command-line tool that scans Python environments, project dependencies, and requirements files for known vulnerabilities.

Project history

pip-audit was created as a dedicated Python dependency-auditing command and is now hosted by the Python Packaging Authority. It uses vulnerability data from the Python Packaging Advisory Database through PyPI and can also query OSV.

Adoption history

pip-audit became part of the Python Packaging Authority's project ecosystem and is maintained in part by Trail of Bits with support from Google. It is available through PyPI, Homebrew, Nix, conda-forge, pre-commit, and an official GitHub Action.

How it is used

Users run pip-audit against the active Python environment, requirements files, or a local project. It returns status 0 when no known vulnerabilities are found and 1 when vulnerabilities are detected; CI use is supported through pre-commit and an official GitHub Action.

Why package nerds care

pip-audit gives Python users a packaging-aware vulnerability scanner that can resolve dependency trees, consume requirements files, emit CycloneDX SBOMs, and optionally fix vulnerable dependencies. Its security model explicitly distinguishes dependency auditing from static code analysis and malicious-package detection.

Timeline

  • 2021: Early public pip-audit releases established Python dependency vulnerability auditing.
  • Later releases: Added OSV support, CycloneDX output, automatic fixes, environment-variable options, and improved authenticated-index handling.

Related projects

  • pip
  • PyPI
  • Python Packaging Advisory Database
  • OSV
  • CycloneDX
  • pypa/gh-action-pip-audit

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for pip-audit. Package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 2 runtime dependencies.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
pip-auditcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version2.10.1
manager updated2026-09-11
local dataok
upstreamnot checked
latest detectednot detected

https://pypi.org/project/pip-audit/

install metadata

Package metadata

Package keybrew:pip-audit
Version2.10.1
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/pip-audit
Homepagehttps://pypi.org/project/pip-audit/
Upstream docshttps://pypi.org/project/pip-audit/
LicenseApache-2.0
Source archivehttps://files.pythonhosted.org/packages/66/a4/f21d5f0a0edabcbce31560b73c7c5a6f72ae87af4236fd1069c8f59a353d/pip_audit-2.10.1.tar.gz
Last updated2026-09-11T13:04:25Z
Pulseupdated
Dependenciescertifi, python@3.14
Build dependenciesrust
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namepip-audit
Version Scheme1
Revision1
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

pip-audit

nix profile install nixpkgs#pip-audit
  • normalized package name match
  • Matched by: Pip Audit
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/pi/pip-audit/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation