Skip to content

SAST: pip-audit

SAST: pip-audit #204

Workflow file for this run

---
name: "SAST: pip-audit"
on:
pull_request:
branches: ["main"]
push:
branches: ["main"]
schedule:
- cron: "33 4 * * 1" # weekly
permissions:
contents: read
jobs:
pip-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-python@v6
with:
python-version: "3.11"
- name: Set up Python environment
run: |
pip install uv
uv sync --extra "nova-rerun-bridge" --extra "wandelscript" --extra "novax"
- name: Audit dependencies
uses: pypa/gh-action-pip-audit@v1.1.0