Skip to content

Commit e590e84

Browse files
committed
Remove running pip-audit from CI.
pip has had a recent CVE, and as a library (and not an app) it is difficult to run pip-audit in a way that has value but is segregated from pip-audit's own deps such that we don't encounter this kind of false positive. Downstream applications should themselves run pip-audit as it is more suited for being run by applications rather than libraries.
1 parent 5c63fc0 commit e590e84

File tree

1 file changed

+0
-9
lines changed

1 file changed

+0
-9
lines changed

noxfile.py

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -40,15 +40,6 @@ def tests(session):
4040
session.run("pytest", *session.posargs, PACKAGE)
4141

4242

43-
@session()
44-
def audit(session):
45-
"""
46-
Audit dependencies for vulnerabilities.
47-
"""
48-
session.install("pip-audit", ROOT)
49-
session.run("python", "-m", "pip_audit")
50-
51-
5243
@session(tags=["build"])
5344
def build(session):
5445
"""

0 commit comments

Comments
 (0)