Skip to content

Conversation

@jbampton
Copy link
Member

https://github.com/pypa/pip-audit

"Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them"

https://github.com/pypa/pip-audit?tab=readme-ov-file#pre-commit-support

Also used on the Apache Trusted Tooling Release repo:

https://github.com/apache/tooling-trusted-releases/blob/23b3bc5adce730835e0b7d218e14d7e90db13e0e/.pre-commit-config.yaml#L100

Did you read the Contributor Guide?

Is this PR related to a ticket?

  • No:
    • this is a CI update. The PR name follows the format [CI] my subject

What changes were proposed in this PR?

As described above added another check / test to our pre-commit framework.

In the examples it says it works with pyproject.toml files:

https://github.com/pypa/pip-audit?tab=readme-ov-file#examples

How was this patch tested?

With pre-commit

Did this PR include necessary documentation updates?

  • No, this PR does not affect any public API so no need to change the documentation.

@github-actions github-actions bot added the root label Dec 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant