diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index 3ef5b7208..13c05acea 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -38,7 +38,7 @@ jobs: - uses: ./.github/actions/setup-project - name: Create requirements.txt run: pipenv requirements > requirements.txt - - uses: trailofbits/gh-action-pip-audit@v1.0.0 + - uses: pypa/gh-action-pip-audit@v1.0.4 with: inputs: requirements.txt ignore-vulns: PYSEC-2022-237 diff --git a/.github/workflows/daily_checks.yml b/.github/workflows/daily_checks.yml index adbcdca9b..8506d138e 100644 --- a/.github/workflows/daily_checks.yml +++ b/.github/workflows/daily_checks.yml @@ -26,7 +26,7 @@ jobs: - uses: ./.github/actions/setup-project - name: Create requirements.txt run: pipenv requirements > requirements.txt - - uses: trailofbits/gh-action-pip-audit@v1.0.0 + - uses: pypa/gh-action-pip-audit@v1.0.4 with: inputs: requirements.txt ignore-vulns: PYSEC-2022-237 diff --git a/Makefile b/Makefile index 787ff699d..eac26f3db 100644 --- a/Makefile +++ b/Makefile @@ -69,8 +69,10 @@ freeze-requirements: ## create static requirements.txt .PHONY: pip-audit pip-audit: - pipenv run pip-audit -r requirements.txt -l --ignore-vuln PYSEC-2022-237 - -pipenv run pip-audit -r requirements_for_test.txt -l + pipenv requirements > requirements.txt + pipenv requirements --dev > requirements_for_test.txt + pipenv run pip-audit -r requirements.txt --ignore-vuln PYSEC-2022-237 + -pipenv run pip-audit -r requirements_for_test.txt .PHONY: audit audit: npm-audit pip-audit