Merge pull request #95 from GSA/fix-pip-audit

Only run pip-audit on runtime dependencies in CI
This commit is contained in:
Ryan Ahearn
2022-10-19 10:42:35 -04:00
committed by GitHub
3 changed files with 4 additions and 3 deletions

View File

@@ -73,7 +73,7 @@ jobs:
- uses: ./.github/actions/setup-project
- uses: trailofbits/gh-action-pip-audit@v1.0.0
with:
inputs: requirements.txt requirements_for_test.txt
inputs: requirements.txt
ignore-vulns: PYSEC-2022-237
static-scan:

View File

@@ -40,7 +40,7 @@ jobs:
- uses: ./.github/actions/setup-project
- uses: trailofbits/gh-action-pip-audit@v1.0.0
with:
inputs: requirements.txt requirements_for_test.txt
inputs: requirements.txt
ignore-vulns: PYSEC-2022-237
static-scan:

View File

@@ -75,7 +75,8 @@ freeze-requirements: ## Pin all requirements including sub dependencies into req
.PHONY: audit
audit:
pip install --upgrade pip-audit
pip-audit -r requirements.txt -r requirements_for_test.txt -l --ignore-vuln PYSEC-2022-237
pip-audit -r requirements.txt -l --ignore-vuln PYSEC-2022-237
-pip-audit -r requirements_for_test.txt -l
.PHONY: static-scan
static-scan: