Listed in editorial order. Click a column to re-sort the whole list.
Press / to search. Tap a tag to filter. Click any row for details.
Search and filter
Results
| Row number | Tags | |||||
|---|---|---|---|---|---|---|
| 1 | pip-audit Supply Chain Security | 26,189,138 | 1,376 | Supply Chain Security Security | → | |
|
Audits Python environments and dependency trees for known vulnerabilities, using the Python Packaging Advisory Database or OSV.
|
||||||
| 2 | uv-audit Supply Chain Security | Bundled | 90,350 | Supply Chain Security Security | → | |
|
(part of uv) uv's dependency vulnerability scanning backed by OSV.
|
||||||
No projects match your search or filter.
Try a broader term, or .
Supply Chain Security guide
uv audit comes with uv. Run it in your project, and it audits the project's dependencies for known vulnerabilities and for statuses like deprecation and quarantine. By default, it covers every extra and dependency group.
pip-audit scans Python environments for packages with known vulnerabilities, using the Python Packaging Advisory Database. Run pip-audit for the current environment, pip-audit -r requirements.txt for a requirements file, or pip-audit . for a local project. In CI, run it with its official GitHub Action. Only audit a requirements file you would install, since pip-audit -r is functionally equivalent to pip install -r.
Also control what gets installed, since an audit only finds vulnerabilities someone has already reported. For requirements files, pip's docs recommend hash-checking mode to protect against remote tampering. In a uv project, uv's docs suggest a dependency cooldown, which holds back new releases until the community has had a chance to vet them.
Contribute
Know a project that belongs here?
Tell us what it does and why it stands out.