Supply Chain Security

Tools for auditing dependencies against known vulnerabilities.

Audit your dependencies for known vulnerabilities as part of Python supply chain security. A uv project has uv audit built in; other projects run pip-audit.

How to choose:

  • A project managed by uv: uv audit
  • Environments, requirements files, and projects outside uv: pip-audit

Listed in editorial order. Click a column to re-sort the whole list.

Press / to search. Tap a tag to filter. Click any row for details.

Search and filter

Results

Row number Tags
Audits Python environments and dependency trees for known vulnerabilities, using the Python Packaging Advisory Database or OSV.
pypa/github.com/pypa/pip-audit / /26,189,138 downloads/month
(part of uv) uv's dependency vulnerability scanning backed by OSV.

Supply Chain Security guide

uv audit comes with uv. Run it in your project, and it audits the project's dependencies for known vulnerabilities and for statuses like deprecation and quarantine. By default, it covers every extra and dependency group.

pip-audit scans Python environments for packages with known vulnerabilities, using the Python Packaging Advisory Database. Run pip-audit for the current environment, pip-audit -r requirements.txt for a requirements file, or pip-audit . for a local project. In CI, run it with its official GitHub Action. Only audit a requirements file you would install, since pip-audit -r is functionally equivalent to pip install -r.

Also control what gets installed, since an audit only finds vulnerabilities someone has already reported. For requirements files, pip's docs recommend hash-checking mode to protect against remote tampering. In a uv project, uv's docs suggest a dependency cooldown, which holds back new releases until the community has had a chance to vet them.

Know a project that belongs here?

Tell us what it does and why it stands out.