Skip to main content

Poetry Audit Plugin

Poetry plugin for checking security vulnerabilities in dependencies based on safety.

$ poetry audit
Scanning 19 packages...

  • ansible-runner     installed 1.1.2  affected <1.3.1   CVE PVE-2021-36995
  • ansible-tower-cli  installed 3.1.8  affected <3.2.0   CVE CVE-2020-1733 
  • jinja2             installed 2.0    affected <2.11.3  CVE CVE-2020-28493

3 vulnerabilities found

Installation

The easiest way to install the audit plugin is via the self add command of Poetry.

poetry self add poetry-audit-plugin

If you used pipx to install Poetry you can add the plugin via the pipx inject command.

pipx inject poetry poetry-audit-plugin

Otherwise, if you used pip to install Poetry you can add the plugin packages via the pip install command.

pip install poetry-audit-plugin

Available options

  • --json: Export the result in JSON format.
poetry audit --json
  • --ignore-code: Ignore some vulnerabilities IDs. Receive a list of IDs. For example:
poetry audit --ignore-code=CVE-2022-42969,CVE-2020-10684
  • --ignore-package: Ignore some packages. Receive a list of packages. For example:
poetry audit --ignore-package=ansible-tower-cli
  • --proxy-protocol, --proxy-host, --proxy-port: Proxy to access Safety DB. For example:
poetry audit --proxy-protocol=http --proxy-host=localhost --proxy-port=3128
  • --cache-sec: How long Safety DB can be cached locally. For example:
poetry audit --cache-sec=60
  • --db: Path to a local or remote vulnerability database of Safety. For example:
poetry audit --db=/path/to/safety.json

Exit codes

poetry audit will exit with a code indicating its status.

  • 0: Vulnerabilities were not found.
  • 1: One or more vulnerabilities were found.
  • Others: Something wrong happened.

Develop poetry-audit-plugin

You can read this document to setup an environment to develop poetry-audit-plugin.

First step is to install Poetry. Please read official document and install Poetry in your machine.

Then, you can install dependencies of poetry-audit-plugin and activate the environment with the following command.

poetry install
source .venv/bin/activate

Once you've done it, you can start developing poetry-audit-plugin. You can use test assets for the testing.

cd tests/assets/no_vulnerabilities_project
poetry audit

Please lint, format, and test your changes before creating pull request to keep the quality.

./scripts/lint.sh
./scripts/format.sh
./scripts/test.sh

Contribution

Help is always appreciated. Please feel free to create issue and pull request!

License

This project is licensed under the terms of the MIT license.

Release files for poetry-audit-plugin 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for poetry-audit-plugin 1.0.0
File Size Uploaded
poetry_audit_plugin-1.0.0.tar.gz 7.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for poetry-audit-plugin 1.0.0
File Interpreter ABI Platform
poetry_audit_plugin-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 16.2 kB

Release files / poetry_audit_plugin-1.0.0.tar.gz

Download URL poetry_audit_plugin-1.0.0.tar.gz
Size 7.0 kB
Tags Source
SHA-256 checksum
How to use checksums
6810aa9859769bb75ae4b1657b21eaafe111d9f89782eaf5ed686356d2ab67e6
BLAKE2b-256 checksum
How to use checksums
22de7bbf41ef8354f858959c637bdf11a82b716cd2de4fd845c054b4fa225782
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.2.1 CPython/3.12.12 Linux/6.11.0-1018-azure

Release files / poetry_audit_plugin-1.0.0-py3-none-any.whl

Download URL poetry_audit_plugin-1.0.0-py3-none-any.whl
Size 9.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a5ea8e39834e47619ff85ddb9805400ed7bef89307b1887b5b18500cb0a2d258
BLAKE2b-256 checksum
How to use checksums
d5d9ec82728eceeccb36ade9e09b325afa380fd23e14fa1dfc6e51370b7152f6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.2.1 CPython/3.12.12 Linux/6.11.0-1018-azure

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page