pypa / gh-action-pip-audit
A GitHub Action for pip-audit
☆72Updated 3 weeks ago
Alternatives and similar repositories for gh-action-pip-audit:
Users that are interested in gh-action-pip-audit are comparing it to the libraries listed below
- A Sigstore client written in Python☆249Updated this week
- A GitHub Action for sigstore-python☆48Updated 2 weeks ago
- This is a repository of vulnerability advisories for projects in scope for the Python Software Foundation CVE Numbering Authority (CNA)☆30Updated last month
- 🕵️ File browser for distributions on PyPI☆99Updated this week
- Data about packages and maintainers on PyPI☆125Updated 2 months ago
- Update GitHub Actions version pins in GitHub workflow files.☆26Updated 4 months ago
- Scans Python packages for abi3 violations and inconsistencies☆104Updated this week
- Automatically updated pypi API data, available in bulk via git or sqlite☆69Updated this week
- An open-source collection of API key rotation tutorials.☆63Updated last month
- This repo scans pypi for AWS keys☆106Updated 10 months ago
- a mostly correct pip requirements parsing library☆20Updated 4 months ago
- Dlint is a tool for encouraging best coding practices and helping ensure Python code is secure.☆162Updated 2 months ago
- python dependency vulnerability scanner, written in Rust.☆195Updated last month
- You made a thing, but now you wish it'd go away... Deprecations, a love story.☆14Updated 2 months ago
- Github Action support for tox 4 and later☆56Updated this week
- Validation library for simple check on `pyproject.toml`☆144Updated this week
- Check your Python environments for vulnerable Open Source packages with OSS Index or Sonatype Nexus Lifecycle.☆116Updated 2 months ago
- Fetches security vulnerabilities and creates pip-constraints based on them.☆12Updated this week
- Advisory database for Python packages published on pypi.org☆271Updated this week
- ☆175Updated this week
- tool for sniffing images over HTTP traffic and showing them on the console. Designed for remote shells.☆12Updated 4 years ago
- Format agnostic SBOM tooling☆96Updated this week
- 🌈 Drop-in replacement for Click to make user-friendly and colorful CLI☆77Updated this week
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆188Updated last week
- A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disc…☆119Updated last week
- A parser for Python dependency files☆64Updated 2 months ago
- Packaging improvements that could be funded☆54Updated last year
- Simple, composable command runner for Python projects☆30Updated 4 months ago
- Python module for OpenPGP written in Rust.☆52Updated 2 weeks ago
- next.js website powering https://py-code.org/☆30Updated 2 months ago