
Prüft Python-Umgebungen, Requirements-Dateien und Abhängigkeitsbäume auf bekannte Sicherheitsschwachstellen und kann diese automatisch beheben
pip-audit ist ein Tool zum Durchsuchen von Python-Umgebungen nach Paketen mit bekannten Sicherheitslücken. Es nutzt die Python Packaging Advisory Database (https://github.com/pypa/advisory-database) über die PyPI JSON API als Quelle für Schwachstellenberichte.
Dieses Projekt wird zum Teil von Trail of Bits mit Unterstützung von Google gepflegt. Es handelt sich nicht um ein offizielles Google- oder Trail-of-Bits-Produkt.
--fix)pip-Cachespip-audit erfordert Python 3.10 oder neuer und kann direkt über pip installiert werden:```bash
python -m pip install pip-audit
### Pakete von Drittanbietern
Es gibt mehrere **Pakete von Drittanbietern** für `pip-audit`. Die untenstehenden Matrizen und Badges listen einige davon auf:
[](https://repology.org/project/python:pip-audit/versions)
[](https://repology.org/project/pip-audit/versions)
[][#conda-forge-package]
[][#conda-forge-package]
[#conda-forge-package]: https://anaconda.org/conda-forge/pip-audit
Insbesondere kann `pip-audit` über `conda` installiert werden:```bash
conda install -c conda-forge pip-audit
Paketverwaltungen von Drittanbietern werden von diesem Projekt nicht direkt unterstützt. Bitte konsultieren Sie die Dokumentation Ihres Paketverwalters für detailliertere Installationsanleitungen.
pip-audit hat eine offizielle GitHub Action!
Sie können sie aus dem GitHub Marketplace installieren oder manuell zu Ihrer CI hinzufügen:```yaml jobs: pip-audit: steps: - uses: pypa/[email protected] with: inputs: requirements.txt
Siehe die
[Aktionsdokumentation](https://github.com/pypa/gh-action-pip-audit/blob/main/README.md)
für weitere Details und Nutzungsbeispiele.
### `pre-commit` Unterstützung
`pip-audit` hat [`pre-commit`](https://pre-commit.com/) Unterstützung.
Zum Beispiel die Verwendung von `pip-audit` über `pre-commit` zur Überprüfung einer Requirements-Datei:```yaml
- repo: https://github.com/pypa/pip-audit
rev: v2.10.1
hooks:
- id: pip-audit
args: ["-r", "requirements.txt"]
ci:
# Leave pip-audit to only run locally and not in CI
# pre-commit.ci does not allow network calls
skip: [pip-audit]
Alle unten dokumentierten pip-audit-Argumente können übergeben werden.
Sie können pip-audit als eigenständiges Programm ausführen oder über python -m:```bash
pip-audit --help
python -m pip_audit --help
<!-- @begin-pip-audit-help@ -->```
usage: pip-audit [-h] [-V] [-l] [-r REQUIREMENT] [--locked] [-f FORMAT]
[-s SERVICE] [--osv-url OSV_URL] [-d] [-S]
[--desc [{on,off,auto}]] [--aliases [{on,off,auto}]]
[--cache-dir CACHE_DIR] [--progress-spinner {on,off}]
[--timeout TIMEOUT] [--path PATH] [-v] [--fix]
[--require-hashes] [--index-url INDEX_URL]
[--extra-index-url URL] [--skip-editable] [--no-deps]
[-o FILE] [--ignore-vuln ID] [--disable-pip]
[project_path]
audit the Python environment for dependencies with known vulnerabilities
positional arguments:
project_path audit a local Python project at the given path
(default: None)