macOS
brew install pip-auditlocal Homebrew formula metadata
brew / Rang 3173
Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für pip-audit in AI-Agent-Workflows.
Installation
brew install pip-auditlocal Homebrew formula metadata
nix profile install nixpkgs#pip-auditnixpkgs package indexes · pkgs/by-name/pi/pip-audit/package.nix · Quelle: api.github.com
Überblick
Audits Python environments and dependency trees for known vulnerabilities
Verlauf
pip-audit is a PyPA command-line tool that scans Python environments, project dependencies, and requirements files for known vulnerabilities.
pip-audit was created as a dedicated Python dependency-auditing command and is now hosted by the Python Packaging Authority. It uses vulnerability data from the Python Packaging Advisory Database through PyPI and can also query OSV.
pip-audit became part of the Python Packaging Authority's project ecosystem and is maintained in part by Trail of Bits with support from Google. It is available through PyPI, Homebrew, Nix, conda-forge, pre-commit, and an official GitHub Action.
Users run pip-audit against the active Python environment, requirements files, or a local project. It returns status 0 when no known vulnerabilities are found and 1 when vulnerabilities are detected; CI use is supported through pre-commit and an official GitHub Action.
pip-audit gives Python users a packaging-aware vulnerability scanner that can resolve dependency trees, consume requirements files, emit CycloneDX SBOMs, and optionally fix vulnerable dependencies. Its security model explicitly distinguishes dependency auditing from static code analysis and malicious-package detection.
Sicherheitslage
Für pip-audit wurde kein passendes lokales Secret-Handling-Manifest gefunden. Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.
Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.
Executables
| Befehl | Art | Sichtbarkeit | Hinweis |
|---|---|---|---|
pip-audit | cli | globales Executable |
Aktualität
Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.
https://pypi.org/project/pip-audit/
Installationsmetadaten
| Paketschlüssel | brew:pip-audit |
|---|---|
| Version | 2.10.1 |
| Paketmanager | Homebrew |
| Paketmanager-Seite | https://formulae.brew.sh/formula/pip-audit |
| Homepage | https://pypi.org/project/pip-audit/ |
| Upstream-Dokumentation | https://pypi.org/project/pip-audit/ |
| Lizenz | Apache-2.0 |
| Quellarchiv | https://files.pythonhosted.org/packages/66/a4/f21d5f0a0edabcbce31560b73c7c5a6f72ae87af4236fd1069c8f59a353d/pip_audit-2.10.1.tar.gz |
| Zuletzt aktualisiert | 2026-09-11T13:04:25Z |
| Pulse | updated |
| Abhängigkeiten | certifi, python@3.14 |
| Build-Abhängigkeiten | rust |
| Bottle | verfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | nicht definiert |
| Dienst | keiner deklariert |
Registry-Fakten
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | pip-audit |
| Version Scheme | 1 |
| Revision | 1 |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
Source-Datenbank-Treffer
Treffer stammen aus externen Paketmanager-Indizes und bleiben von lokalen Automic-Vault-Paketlinks getrennt.
pip-audit
nix profile install nixpkgs#pip-auditQuellspur
Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.
View the package source record on GitHub.