psf / advisory-databaseLinks
This is a repository of vulnerability advisories for projects in scope for the Python Software Foundation CVE Numbering Authority (CNA)
☆35Updated last week
Alternatives and similar repositories for advisory-database
Users that are interested in advisory-database are comparing it to the libraries listed below
Sorting:
- Data about packages and maintainers on PyPI☆128Updated 2 months ago
- A Sigstore client written in Python☆276Updated last week
- 🕵️ File browser for distributions on PyPI☆105Updated 2 weeks ago
- A GitHub Action for sigstore-python☆53Updated 2 weeks ago
- A GitHub Action for pip-audit☆75Updated 2 weeks ago
- Packaging improvements that could be funded☆54Updated 2 years ago
- Software Bill-of-Materials documents for Python packages☆41Updated 4 months ago
- Canonical source for classifiers on PyPI.☆161Updated 2 months ago
- Check for stylistic and formal issues in .rst and .py files included in the documentation☆88Updated 2 weeks ago
- Update GitHub Actions version pins in GitHub workflow files.☆31Updated this week
- Advisory database for Python packages published on pypi.org☆296Updated this week
- a GitHub action to install (pre-release) pythons from deadsnakes☆56Updated 3 weeks ago
- Python implementation of the package url spec. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase…☆75Updated 3 weeks ago
- Resolve abstract dependencies into concrete ones☆156Updated 3 weeks ago
- CLI to open PEPs in your browser☆37Updated last week
- A parser for Python dependency files☆65Updated 7 months ago
- Automatically updated pypi API data, available in bulk via git or sqlite☆78Updated this week
- Ooops, I wrote another Sphinx theme! [very WIP, do not use]☆39Updated last week
- PEP 621 metadata parsing☆41Updated last week
- Dlint is a tool for encouraging best coding practices and helping ensure Python code is secure.☆167Updated 8 months ago
- CLI to show end-of-life dates for a number of products.☆129Updated last week
- Verify certificates using OS trust stores☆188Updated this week
- ☆41Updated 5 months ago
- A Python library to parse, validate and create SPDX documents.☆219Updated last week
- A low-level library for installing from a Python wheel distribution.☆137Updated last week
- A low-level library for calling build-backends in `pyproject.toml`-based project☆127Updated last month
- An unofficial, importable pip API☆114Updated 3 weeks ago
- 🐍🍒⛏ Utility script for backporting/cherry-picking CPython changes from master into one of the maintenance branches.☆55Updated last week
- ☆185Updated last week
- Issue tracker for support requests related to using https://pypi.org☆105Updated 3 months ago