Skip to content

extend check-vulnerarabilities with uv audit (experimental) #1458

Description

@SMoraisAnsys

Here is a blog post on uv audit and the associated roadmap can be found here.

Given the status of uv audit (experimental) this might be something to opt-in.

Note

When I tried it, it was able to provide feedback on vulnerability that safety wasn't providing.

Extra: we should share uv sync operations can perform lightweight OSV-based lookup for previously-resolved malware. This can now be configured with pyproject.toml settings since this PR and is available in uv's versions above v0.11.31

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions