pip-audit 是一个用于扫描 Python 环境中已知漏洞包的工具。它通过 PyPI JSON API 使用 Python 打包咨询数据库 (https://github.com/pypa/advisory-database) 作为漏洞报告的来源。
该项目由 Trail of Bits 部分维护,并得到 Google 的支持。这不是 Google 或 Trail of Bits 的官方产品。
--fix)pip 缓存pip-audit 需要 Python 3.10 或更新版本,并可通过 pip 直接安装:```bash
python -m pip install pip-audit
### 第三方包
`pip-audit` 有多个 **第三方** 包。以下矩阵和徽章列举了其中一些:
[](https://repology.org/project/python:pip-audit/versions)
[](https://repology.org/project/pip-audit/versions)
[][#conda-forge-package]
[][#conda-forge-package]
[#conda-forge-package]: https://anaconda.org/conda-forge/pip-audit
特别是,`pip-audit` 可以通过 `conda` 安装:```bash
conda install -c conda-forge pip-audit
第三方软件包不受本项目直接支持。请查阅您的包管理器文档以获取更详细的安装指南。
pip-audit 有一个官方 GitHub Action!
您可以从 GitHub Marketplace 安装它,或者手动添加到您的 CI:```yaml jobs: pip-audit: steps: - uses: pypa/[email protected] with: inputs: requirements.txt
查阅
[操作文档](https://github.com/pypa/gh-action-pip-audit/blob/main/README.md)
获取更多详情和使用示例。
### `pre-commit` 支持
`pip-audit` 支持 [`pre-commit`](https://pre-commit.com/)。
例如,通过 `pre-commit` 使用 `pip-audit` 审计 requirements 文件:```yaml
- repo: https://github.com/pypa/pip-audit
rev: v2.10.1
hooks:
- id: pip-audit
args: ["-r", "requirements.txt"]
ci:
# Leave pip-audit to only run locally and not in CI
# pre-commit.ci does not allow network calls
skip: [pip-audit]
以下文档中描述的任何 pip-audit 参数都可以传递。
你可以将 pip-audit 作为独立程序运行,或者通过 python -m 运行:```bash
pip-audit --help
python -m pip_audit --help
<!-- @begin-pip-audit-help@ -->```
usage: pip-audit [-h] [-V] [-l] [-r REQUIREMENT] [--locked] [-f FORMAT]
[-s SERVICE] [--osv-url OSV_URL] [-d] [-S]
[--desc [{on,off,auto}]] [--aliases [{on,off,auto}]]
[--cache-dir CACHE_DIR] [--progress-spinner {on,off}]
[--timeout TIMEOUT] [--path PATH] [-v] [--fix]
[--require-hashes] [--index-url INDEX_URL]
[--extra-index-url URL] [--skip-editable] [--no-deps]
[-o FILE] [--ignore-vuln ID] [--disable-pip]
[project_path]
audit the Python environment for dependencies with known vulnerabilities
positional arguments:
project_path audit a local Python project at the given path
(default: None)