Files

17 lines
831 B
Plaintext

# pip-audit for the security.yml `dependency-scan` job, hash-pinned (Scorecard:
# Pinned-Dependencies).
#
# Target env: ubuntu-latest, Python 3.13. pip-audit's own dependency tree is
# resolved and hashed here; the project itself is still installed unpinned via
# `pip install -e .` and scanned with `pip-audit --skip-editable`, so pinning
# this file does not narrow what the audit covers.
#
# TRADE-OFF: pip-audit scans the whole environment, including its own deps. They
# used to float to latest on every run (self-healing); pinned, a new advisory
# against one of them reds this job until the pin moves. Dependabot's `pip`
# entry for /.github/requirements is what keeps that window short.
#
# Regenerate:
# pip-compile --allow-unsafe --generate-hashes --no-emit-index-url --output-file=audit.txt audit.in
pip-audit==2.10.1