Sitelet https://web.archive.org/web/20221205104506/https://github.com/Homebrew/brew-pip-audit
Skip to content

Homebrew/brew-pip-audit

main
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Code

Latest commit

 

Git stats

Files

Permalink
Failed to load latest commit information.
Type
Name
Latest commit message
Commit time
 
 
 
 
 
 
 
 
 
 

brew-pip-audit: Bulk auditing Python dependencies in Homebrew with pip-audit

Homebrew is a popular package manager for macOS. Many of the projects it packages are written in Python. In order to ensure reproducible builds, Homebrew precisely pins the version of each Python package a Homebrew formula depends on.

pip-audit is a tool for checking a Python project's dependencies against vulnerability databases in order to determine if there are any known vulnerabilities.

This project takes all of the Python packages depended on by Homebrew formulas and runs them through pip-audit.

The repo

The following things can be found in this repository:

  • formula2requirements.rb: Extracts the Python dependencies from Homebrew and writes them out in the requirements.txt format.
  • pip-audit-bulk: Runs pip-audit over a directory of requirements.txt files.
  • requirements/: The extracted requirements.txt file for each Homebrew formula.
  • audits/: The result of pip-audit for each Homebrew formula. There will only be a file present if vulnerabilities were found.

requirements/ and audits/ are automatically refreshed on a daily basis by Github Actions.

Contributing

The best way to contribute is to take Homebrew formulas with known vulnerabilities (i.e. ones in audits/) and get them fixed. Sometimes this means upgrading the pinned versions in Homebrew, other times this may mean contributing to the project's upstream to bump the version.

About

📋 Bulk auditing Python dependencies in Homebrew with pip-audit

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 4

  •  
  •  
  •  
  •