Announcing uv audit: native support for vulnerability scanning across your project's dependencies
Astral founder Charlie Marsh launches uv audit to bring native dependency vulnerability scanning to the Python toolchain
It also introduces experimental malware detection during dependency resolution.
Users are excited about uv adding native vulnerability scanning for Python project dependencies because it offers a convenient built-in security improvement.
No Digg Deeper questions have been answered for this story yet.
Most Activity
https://astral.sh/blog/uv-audit
We also now support on-the-fly malware checks via the Open Source Vulnerabilities (OSV) database.
Set UV_MALWARE_CHECK=1, and we'll cross-reference your resolved dependencies with known malware reports prior to installation.
We also now support on-the-fly malware checks via the Open Source Vulnerabilities (OSV) database.
Set UV_MALWARE_CHECK=1, and we'll cross-reference your resolved dependencies with known malware reports prior to installation.
Announcing uv audit: native support for vulnerability scanning across your project's dependencies
All credit here goes to our security king William Woodruff
https://github.com/woodruffw
https://astral.sh/blog/uv-audit
@charliermarsh thank you mr uv
Announcing uv audit: native support for vulnerability scanning across your project's dependencies

@charliermarsh Omg ♥️

@charliermarsh Yesss