
Python 환경, requirements 파일 및 종속성 트리를 감사하여 알려진 보안 취약점을 찾고 자동으로 수정할 수 있습니다.
pip-audit는 알려진 취약점이 있는 패키지를 검색하기 위해 Python 환경을 스캔하는 도구입니다. 이 도구는 취약점 보고서 소스로 PyPI JSON API를 통해 Python Packaging Advisory Database(https://github.com/pypa/advisory-database)를 사용합니다.
이 프로젝트는 Google의 지원을 받아 Trail of Bits가 부분적으로 유지 관리합니다. 이는 공식 Google 또는 Trail of Bits 제품이 아닙니다.
--fix)pip 캐시를 원활하게 재사용pip-audit는 Python 3.10 이상이 필요하며, pip를 통해 직접 설치할 수 있습니다:```bash
python -m pip install pip-audit
### 서드파티 패키지
`pip-audit`을 위한 여러 **서드파티** 패키지가 있습니다. 아래의 행렬과 배지에는 그중 일부가 나와 있습니다:
[](https://repology.org/project/python:pip-audit/versions)
[](https://repology.org/project/pip-audit/versions)
[][#conda-forge-package]
[][#conda-forge-package]
[#conda-forge-package]: https://anaconda.org/conda-forge/pip-audit
특히, `pip-audit`은 `conda`를 통해 설치할 수 있습니다:```bash
conda install -c conda-forge pip-audit
타사 패키지는 이 프로젝트에서 직접 지원되지 않습니다. 더 자세한 설치 지침은 패키지 관리자의 문서를 참조하세요.
pip-audit에는 공식 GitHub Action이 있습니다!
GitHub 마켓플레이스에서 설치하거나, 수동으로 CI에 추가할 수 있습니다:```yaml jobs: pip-audit: steps: - uses: pypa/[email protected] with: inputs: requirements.txt
자세한 내용과 사용 예시는 [액션 문서](https://github.com/pypa/gh-action-pip-audit/blob/main/README.md)를 참조하세요.
### `pre-commit` 지원
`pip-audit`은 [`pre-commit`](https://pre-commit.com/)을 지원합니다.
예를 들어, `pre-commit`을 통해 `pip-audit`을 사용하여 요구 사항 파일을 감사하는 경우:```yaml
- repo: https://github.com/pypa/pip-audit
rev: v2.10.1
hooks:
- id: pip-audit
args: ["-r", "requirements.txt"]
ci:
# Leave pip-audit to only run locally and not in CI
# pre-commit.ci does not allow network calls
skip: [pip-audit]
아래 문서화된 모든 pip-audit 인수를 전달할 수 있습니다.
pip-audit를 독립 실행형 프로그램으로 실행하거나 python -m을 통해 실행할 수 있습니다.```bash
pip-audit --help
python -m pip_audit --help
<!-- @begin-pip-audit-help@ -->```
usage: pip-audit [-h] [-V] [-l] [-r REQUIREMENT] [--locked] [-f FORMAT]
[-s SERVICE] [--osv-url OSV_URL] [-d] [-S]
[--desc [{on,off,auto}]] [--aliases [{on,off,auto}]]
[--cache-dir CACHE_DIR] [--progress-spinner {on,off}]
[--timeout TIMEOUT] [--path PATH] [-v] [--fix]
[--require-hashes] [--index-url INDEX_URL]
[--extra-index-url URL] [--skip-editable] [--no-deps]
[-o FILE] [--ignore-vuln ID] [--disable-pip]
[project_path]
audit the Python environment for dependencies with known vulnerabilities
positional arguments:
project_path audit a local Python project at the given path
(default: None)