pkg.soopen package index

brew / Rang 3173

pip-audit mit Homebrew, Nix installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für pip-audit in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install pip-audit

local Homebrew formula metadata

Linux

Nixverifiziert · 92%
nix profile install nixpkgs#pip-audit

nixpkgs package indexes · pkgs/by-name/pi/pip-audit/package.nix · Quelle: api.github.com

Überblick

Paketzusammenfassung

Audits Python environments and dependency trees for known vulnerabilities

Befehle und Aliase

  • pip-audit

Verlauf

Projektgeschichte und Nutzung

pip-audit is a PyPA command-line tool that scans Python environments, project dependencies, and requirements files for known vulnerabilities.

Projektgeschichte

pip-audit was created as a dedicated Python dependency-auditing command and is now hosted by the Python Packaging Authority. It uses vulnerability data from the Python Packaging Advisory Database through PyPI and can also query OSV.

Adoptionsgeschichte

pip-audit became part of the Python Packaging Authority's project ecosystem and is maintained in part by Trail of Bits with support from Google. It is available through PyPI, Homebrew, Nix, conda-forge, pre-commit, and an official GitHub Action.

Wie es verwendet wird

Users run pip-audit against the active Python environment, requirements files, or a local project. It returns status 0 when no known vulnerabilities are found and 1 when vulnerabilities are detected; CI use is supported through pre-commit and an official GitHub Action.

Warum Paket-Nerds sich dafür interessieren

pip-audit gives Python users a packaging-aware vulnerability scanner that can resolve dependency trees, consume requirements files, emit CycloneDX SBOMs, and optionally fix vulnerable dependencies. Its security model explicitly distinguishes dependency auditing from static code analysis and malicious-package detection.

Zeitleiste

  • 2021: Early public pip-audit releases established Python dependency vulnerability auditing.
  • Later releases: Added OSV support, CycloneDX output, automatic fixes, environment-variable options, and improved authenticated-index handling.

Related projects

  • pip
  • PyPI
  • Python Packaging Advisory Database
  • OSV
  • CycloneDX
  • pypa/gh-action-pip-audit

Sicherheitslage

Noch keine Protected-Tool-Abdeckung gefunden

Für pip-audit wurde kein passendes lokales Secret-Handling-Manifest gefunden. Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Installiert mit 2 Laufzeitabhängigkeiten.
  • Build-Metadaten listen 1 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
pip-auditcliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-09-19
Manager-Version2.10.1
Manager aktualisiert2026-09-11
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://pypi.org/project/pip-audit/

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:pip-audit
Version2.10.1
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/pip-audit
Homepagehttps://pypi.org/project/pip-audit/
Upstream-Dokumentationhttps://pypi.org/project/pip-audit/
LizenzApache-2.0
Quellarchivhttps://files.pythonhosted.org/packages/66/a4/f21d5f0a0edabcbce31560b73c7c5a6f72ae87af4236fd1069c8f59a353d/pip_audit-2.10.1.tar.gz
Zuletzt aktualisiert2026-09-11T13:04:25Z
Pulseupdated
Abhängigkeitencertifi, python@3.14
Build-Abhängigkeitenrust
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namepip-audit
Version Scheme1
Revision1
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

Source-Datenbank-Treffer

Andere Paketmanager-Einträge

Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.

Nix95%

pip-audit

nix profile install nixpkgs#pip-audit
  • normalized package name match
  • Abgeglichen nach: Pip Audit
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/pi/pip-audit/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation