pdm-audit
A PDM plugin that scans your Python project dependencies for known vulnerabilities. It leverages pip-audit to provide security auditing capabilities within your PDM workflow.
Features
- Multiple vulnerability data sources support
- PyPI vulnerability database via the PyPI JSON API
- OSV database support
- Multiple output formats:
- Columnar (default)
- JSON
- Markdown
- Caching support with configurable time-to-live (TTL)
- Seamless integration with PDM's dependency management
Installation
pdm self add pdm-audit-plugin
Usage
Run pdm audit in your project directory:
pdm audit --help
Command Options
Options:
-s, --service The audit source. Default is PyPI, can be pypi, osv.
-f, --format The format to emit audit results in (choices: columns, json, markdown)
--desc Include vulnerability descriptions (auto, on, off)
--enable-cache Enable the vulnerability query result cache
--cache-ttl The cache time-to-live in seconds (default: 1800)
Examples
Basic audit of project dependencies:
pdm audit
Using OSV as the vulnerability database:
pdm audit -s osv
Output in JSON format:
pdm audit -f json
Output in Markdown format:
pdm audit -f markdown
Disable caching:
pdm audit --enable-cache false
Customize cache TTL to 1 hour:
pdm audit --cache-ttl 3600
Security Model
This plugin inherits its security model from pip-audit. Please note:
- It identifies known vulnerabilities in your dependencies based on data from vulnerability databases
- It cannot detect undisclosed vulnerabilities or perform static code analysis
- The audit is only as accurate as the vulnerability data available in the chosen service (PyPI or OSV)
Cache Management
The plugin maintains a cache of vulnerability data to improve performance:
- Default cache location:
.audit_cachein your project directory - Default TTL: 1800 seconds (30 minutes)
- Cache can be disabled or customized via command options
Troubleshooting
Slow Audit Performance
- First-time audits may be slower due to cache population
- Subsequent audits will be faster if caching is enabled
- Consider adjusting cache TTL if needed
Connection Issues
If you encounter connection errors:
- Verify your internet connection
- Check if you're behind a corporate proxy
- Try switching between PyPI and OSV services
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
License
This project is licensed under the MIT License.
Metadata
Release files for pdm-audit-plugin 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pdm_audit_plugin-0.1.2.tar.gz | 4.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pdm_audit_plugin-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 9.1 kB
Release files / pdm_audit_plugin-0.1.2.tar.gz
| Download URL | pdm_audit_plugin-0.1.2.tar.gz |
|---|---|
| Size | 4.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2fa4fee2a4c95d10c69d243f076e3cc002992a9d977abd47ad1c34021b0a3b8f
|
|
BLAKE2b-256 checksum How to use checksums |
005f2521c65e30134bf9a772566b7c21fac3e3cffba8c635dd2fcd9854f775c9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
pdm/2.21.0 CPython/3.13.0 Linux/6.12.1-manjusakav4-xanmod2-2-manjusaka
|
Release files / pdm_audit_plugin-0.1.2-py3-none-any.whl
| Download URL | pdm_audit_plugin-0.1.2-py3-none-any.whl |
|---|---|
| Size | 4.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1369c376e4c6c1ee44ae5e1e3a6f80766f7e5aadd5975fa09b929e053eefcb03
|
|
BLAKE2b-256 checksum How to use checksums |
0ff5e70d9af07d9b30efbb2d0f566a73a72d24f38e93258a55a7a4eab793f65f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
pdm/2.21.0 CPython/3.13.0 Linux/6.12.1-manjusakav4-xanmod2-2-manjusaka
|