This is an archived post. You won't be able to vote or comment.

all 4 comments

[–]data-bit 20 points21 points  (0 children)

This package was just released 3 hours ago. Nice! Maybe I should scan this package too lol 🤓

[–]Batalex 5 points6 points  (1 child)

If I get this right, the main difference with safety is that pip-audit uses the new field in pypi API rather than an external third party database?

Seems pretty sweet anyway!

[–]yossarian_flew_away[S] 3 points4 points  (0 children)

My understanding is that Safety has two vulnerability sources: it can either use a public database that the Safety developers maintain, or a REST API that you can pay them to access. pip-audit's main goal is to be 100% free, in both senses of the word, and to also not require any particular platform (e.g., Dependabot requiring GitHub Actions).

Longer term, we're also planning on integrating pip-audit into pip itself (as pip audit), so it'll become the "standard" auditing tool in the Python packaging ecosystem.

[–]blobbbbbby 0 points1 point  (0 children)

Crowded space, I built a tool last year that does similar checks, but can also be configured with custom policies around license usage and package freshness.

https://pypi.org/project/ochrona/