NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #656 most downloaded on PyPI
A tool for scanning Python environments for known vulnerabilities
Last release 3 months ago
10 Jun 2026
Release timing varies
gaps range from 2 weeks to 9 months
Most releases are documented
notes for 50 of 58 stable releases
1 version withdrawn
withdrawn after publishing
5 years old
63 releases · first in 2021
One column per quarter.
Fixed a KeyError crash when an OSV vulnerability record contains an affected entry that omits the optional ranges field
KeyError crash when an OSV vulnerability record contains anaffected entry that omits the optional ranges fieldpip-audit now supports the --osv-url URL flag, which can be used to retrieve vulnerabilities from a custom OSV service. This is useful for organizatio…
pip-audit now supports the --osv-url URL flag, which can be used to
retrieve vulnerabilities from a custom OSV service. This is useful for
organizations that host their own mirror of the OSV database, or that
have custom OSV records
(#810)
pip-audit now supports the Ecosyste.ms vulnerability service with
--vulnerability-service=esms
(#903).
pip-audit now supports PEP 751 lockfiles. These lockfiles can be audited in "project" mode by passing --locked to pip-audit
pip-audit now allows some CLI flags to be configured via environment variables
pip-audit now allows some CLI flags to be configured via environment
variables (#755)The default cache locations on macOS and Linux now respect each platform's caching directory idioms (e.g. XDG) (#814)
The minimum version of Python is now 3.9 (#846)
Improved handling of temporary files on Windows
pip-audit now invokes pip with --keyring-provider=subprocess , partially fixing a regression that was introduced with another authentication fix in 2.
pip-audit now invokes pip with --keyring-provider=subprocess,pip to use keyring to performFull Changelog: v2.7.1...v2.7.2
Improved the error returned to users when their default temporary directory lacks execute permissions
pip-audit now includes vulnerability aliases when --format=json is used, and also includes them in other output formats if specified by adding the fla…
pip-audit now includes vulnerability aliases when --format=json is used,--aliasesRemoved a misleading warning message that resulted in user confusion
pip-audit 's minimum Python version is now 3.8.
pip-audit's minimum Python version is now 3.8.pip to wait indefinitelyFixed a crash on Windows caused by pip-audit's use of temporary files
pip-audit's use of temporary files
(#647)Added option to skip dependency resolution via pip with the --disable-pip flag. This option can only be used with hashed requirements files or when th
pip with the --disable-pip
flag. This option can only be used with hashed requirements files or when the
--no-deps flag has been provided
(#610)Fixed a crash caused by incompatible dependency changes
Fixed a crash caused by incompatible dependency changes
Refactored index-url option to not override user pip config by default, unless specified
index-url option to not override user pip config by default,
unless specified (#565)Further simplified pip-audit's dependency resolution to remove inconsistent behaviour when using hashed requirements or the --no-deps flag
Fixed a loose dependency constraint for CycloneDX SBOM generation
Fixed a crash on Windows caused by multiple open file handles to input requirements
Improved error messaging when a requirements input or indirect dependency has an invalid (non-PEP 440) requirements specifier
Improved error messaging when a requirements input or indirect dependency has an invalid (non-PEP 440) requirements specifier (#507)
pip-audit's handling of dependency resolution has been significantly
refactored and simplified (#523)
Fixed an issue where hash checking would fail when using third-party indices
Fixed an issue where hash checking would fail when using third-party indices (#462)
Fixed the behavior of the --skip-editable flag, which had regressed
with an internal API change
(#499)
Fixed a dependency resolution bug that can potentially be triggered when multiple packages have the same subdependency (#488)
Fixed a dependency resolution failure caused by incorrect handling of a PEP 440 edge case around prerelease versions
Added a lower bound on packaging to ensure that non-normalized versions are handled correctly
packaging to ensure that non-normalized versions
are handled correctly (#471)Fixed pip-audit's virtual environment creation and upgrade behavior, preventing spurious vulnerability reports
Fixed a crash triggered when a package specifies an invalid version specifier for its requires-python version
requires-python version
(#447)Fixed a crash triggered when no vulnerabilities are found with some configurations
The --output flag will no longer produce an empty file in the event of a failure within pip-audit itself, making it easier to distinguish between audi
Pin maximum version of packaging dependency to avoid installing the new 22.0 version which is incompatible with pip-requirements-parser
packaging dependency to avoid installing the new
22.0 version which is incompatible with pip-requirements-parser
(#427)Fixed a timestamp parsing bug that occurred with some vulnerability reports provided by the OSV service
Fixed an incorrect interaction between --desc=auto and --format=json; --desc=auto now includes the description in the generated JSON report, as intend
Fixed an issue where audits done with the PyPI vulnerability service (the default) were not correctly filtered by "withdrawn" status; "withdrawn" vuln…
Fixed an issue where audits done with the PyPI vulnerability service (the default) were not correctly filtered by "withdrawn" status; "withdrawn" vulnerabilities are now excluded (#393)
Fixed an issue where audits done with the OSV vulnerability service (-s osv)
were not correctly filtered by "withdrawn" status; "withdrawn" vulnerabilities
are now excluded (#386)
Fixed pip-audit's handling of URL-style requirements in --no-deps mode
(URL requirements are now treated as skipped, rather than producing
an error due to a lack of pinning)
(#395)
pip-audit is now a PyPA member project, and lives under `pypa/pip-audit`!
pip-audit is now a PyPA member project, and lives under
pypa/pip-audit!
Improved error message for when unpinned URL requirements are found during an
audit with the --no-deps flag
(#355)
Fixed a regression in requirements auditing that was introduced during the move from pip-api to pip-requirements-parser where editable installs withou
CLI: the --format=markdown and --format=columns output formats are no longer broken by long vulnerability descriptions from the OSV and PyPI vulnerabi…
Fixed a breakage in hash-checking mode caused by a change to the PyPI JSON API
Output formats: pip-audit now supports a Markdown format (--format=markdown) which renders results as a set of Markdown tables.
pip-audit now supports a Markdown format
(--format=markdown) which renders results as a set of Markdown tables.
(#312)Vulnerability fixing: the --fix flag now works for vulnerabilities found in requirement subdependencies. A new line is now added to the requirement fi…
--fix flag now works for vulnerabilities found in
requirement subdependencies. A new line is now added to the requirement file
to explicitly pin the offending subdependency
(#297)CLI: pip-audit now warns on the combination of -s osv and --require-hashes, notifying users that only the PyPI service can fully verify hashes
pip-audit now warns on the combination of -s osv and
--require-hashes, notifying users that only the PyPI service
can fully verify hashes
(#298)--cache-dir=... and other flags that affect
dependency resolver behavior now work correctly when auditing a
pyproject.toml dependency source
(#300)CLI, Vulnerability sources: the error message used to report connection failures to vulnerability sources was improved
CLI: pip-audit's progress spinner has been refactored to make it
faster and more responsive
(#283)
CLI, Vulnerability sources: the error message used to report connection failures to vulnerability sources was improved (#287)
Vulnerability sources: the OSV service is now more resilient to schema changes (#288)
Vulnerability sources: the PyPI service provides a better error message during some cases of service degradation (#294)
CLI: A bug causing the terminal's cursor to disappear on some versions of CPython was fixed
CLI: The --ignore-vuln option has been added, allowing users to specify vulnerability IDs to ignore during the final report
CLI: The --ignore-vuln option has been added, allowing users to specify vulnerability IDs to ignore during the final report (https://github.com/trailofbits/pip-audit/pull/275)
CLI: The --no-deps flag has been added, allowing users to skip dependency resolution entirely when pip-audit is used in requirements mode (https://github.com/trailofbits/pip-audit/pull/255)
A bug introduced with a previous fix to version parsing (#263) was fixed
Vulnerability sources: A bug caused by insufficient version normalization was fixed
2.1.1[](https://github.com/trailofbits/pip-audit/blob/main/CHANGELOG.md#fixed) - 2022-03-29
2.1.0[](https://github.com/trailofbits/pip-audit/blob/main/CHANGELOG.md#added) - 2022-03-11
2.1.0 - 2022-03-11
Added
CLI: The --skip-editable flag has been added, allowing users to skip local packages or parsed requirements (via -r) that are marked as editable (https://github.com/trailofbits/pip-audit/pull/244)
CLI: pip-audit can audit projects that list their dependencies in pyproject.toml files, via pip-audit <dir> (https://github.com/trailofbits/pip-audit/pull/246)
CLI: The --fix flag has been added, allowing users to attempt to automatically upgrade any vulnerable dependencies to the first safe version available…
2.0.0 - 2022-02-18
Added
Changed
Fixed
A pin on one of pip-audit's dependencies was fixed
pip-audit's dependencies was fixed
(#213)Dependency sources: a crash caused by unexpected logging statements in pip's JSON output was fixed
pip's
JSON output was fixed
(#196)Vulnerability sources: a performance issue on Windows caused by cache failures was fixed
CLI: The --path <PATH> flag has been added, allowing users to limit
dependency discovery to one or more paths (specified separately)
when pip-audit is invoked in environment mode
(#148)
CLI: The pip-audit CLI can now be accessed through python -m pip_audit.
All functionality is identical to the functionality provided by the
pip-audit entrypoint
(#173)
CLI: The --verbose flag has been added, allowing users to receive more
more verbose output from pip-audit. Supplying the --verbose flag
overrides the PIP_AUDIT_LOGLEVEL environment variable and is equivalent to
setting it to debug
(#185)
pip-audit now clears its spinner bar from the terminal upon
completion, preventing visual confusion
(#174)Dependency sources: a crash caused by platform.python_version returning
an version string that couldn't be parsed as a PEP-440 version was fixed
(#175)
Dependency sources: a crash caused by incorrect assumptions about the structure of source distributions was fixed (#166)
Vulnerability sources: a performance issue on Windows caused by cache failures was fixed (#178)
CLI: The --desc flag no longer requires a following argument. If passed as a bare option, --desc is equivalent to --desc on
CLI: The --desc flag no longer requires a following argument. If passed
as a bare option, --desc is equivalent to --desc on
(#153)
Dependency resolution: The PyPI-based dependency resolver no longer throws
an uncaught exception on package resolution errors; instead, the package
is marked as skipped and an appropriate warning or fatal error (in
--strict mode) is produced
(#162)
CLI: When providing the --cache-dir flag, the command to read the pip cache
directory is no longer executed. Previously this was always executed and
could result into failure when the command fails. In CI environments, the
default ~/.cache directory is typically not writable by the build user and
this meant that the python -m pip cache dir would fail before this fix,
even if the --cache-dir flag was provided.
(#161)
This is the first stable release of pip-audit! The CLI is considered stable from this point on, and all changes will comply with Semantic Versioning
pip-audit! The CLI is considered
stable from this point on, and all changes will comply with
Semantic VersioningCLI: Skipped dependencies are now listed in the output of pip-audit, for supporting output formats
CLI: Skipped dependencies are now listed in the output of pip-audit,
for supporting output formats
(#145)
CLI: pip-audit now supports a "strict" mode (enabled with -S or
--strict) that fails if the audit if any individual dependency cannot be
resolved or audited. The default behavior is still to skip any individual
dependency errors (#146)
<!-- Release URLs --> [Unreleased]: https://github.com/pypa/pip-audit/compare/v2.10.0...HEAD [2.10.0]: https://github.com/pypa/pip-audit/compare/v2.9.0...v2.10.0 [2.9.0]: https://github.com/pypa/pip-audit/compare/v2.8.0...v2.9.0 [2.8.0]: https://github.com/pypa/pip-audit/compare/v2.7.3...v2.8.0 [2.7.3]: https://github.com/pypa/pip-audit/compare/v2.7.2...v2.7.3 [2.7.2]: https://github.com/pypa/pip-audit/compare/v2.7.1...v2.7.2 [2.7.1]: https://github.com/pypa/pip-audit/compare/v2.7.0...v2.7.1 [2.7.0]: https://github.com/pypa/pip-audit/compare/v2.6.3...v2.7.0 [2.6.3]: https://github.com/pypa/pip-audit/compare/v2.6.2...v2.6.3 [2.6.2]: https://github.com/pypa/pip-audit/compare/v2.6.1...v2.6.2 [2.6.1]: https://github.com/pypa/pip-audit/compare/v2.6.0...v2.6.1 [2.6.0]: https://github.com/pypa/pip-audit/compare/v2.5.6...v2.6.0 [2.5.6]: https://github.com/pypa/pip-audit/compare/v2.5.5...v2.5.6 [2.5.5]: https://github.com/pypa/pip-audit/compare/v2.5.4...v2.5.5 [2.5.4]: https://github.com/pypa/pip-audit/compare/v2.5.3...v2.5.4 [2.5.3]: https://github.com/pypa/pip-audit/compare/v2.5.2...v2.5.3 [2.5.2]: https://github.com/pypa/pip-audit/compare/v2.5.1...v2.5.2 [2.5.1]: https://github.com/pypa/pip-audit/compare/v2.5.0...v2.5.1 [2.5.0]: https://github.com/pypa/pip-audit/compare/v2.4.15...v2.5.0 [2.4.15]: https://github.com/pypa/pip-audit/compare/v2.4.14...v2.4.15 [2.4.14]: https://github.com/pypa/pip-audit/compare/v2.4.13...v2.4.14 [2.4.13]: https://github.com/pypa/pip-audit/compare/v2.4.12...v2.4.13 [2.4.12]: https://github.com/pypa/pip-audit/compare/v2.4.11...v2.4.12 [2.4.11]: https://github.com/pypa/pip-audit/compare/v2.4.10...v2.4.11 [2.4.10]: https://github.com/pypa/pip-audit/compare/v2.4.9...v2.4.10 [2.4.9]: https://github.com/pypa/pip-audit/compare/v2.4.8...v2.4.9 [2.4.8]: https://github.com/pypa/pip-audit/compare/v2.4.7...v2.4.8 [2.4.7]: https://github.com/pypa/pip-audit/compare/v2.4.6...v2.4.7 [2.4.6]: https://github.com/pypa/pip-audit/compare/v2.4.5...v2.4.6 [2.4.5]: https://github.com/pypa/pip-audit/compare/v2.4.4...v2.4.5 [2.4.4]: https://github.com/pypa/pip-audit/compare/v2.4.3...v2.4.4 [2.4.3]: https://github.com/pypa/pip-audit/compare/v2.4.2...v2.4.3 [2.4.2]: https://github.com/pypa/pip-audit/compare/v2.4.1...v2.4.2 [2.4.1]: https://github.com/pypa/pip-audit/compare/v2.4.0...v2.4.1 [2.4.0]: https://github.com/pypa/pip-audit/compare/v2.3.4...v2.4.0 [2.3.4]: https://github.com/pypa/pip-audit/compare/v2.3.3...v2.3.4 [2.3.3]: https://github.com/pypa/pip-audit/compare/v2.3.2...v2.3.3 [2.3.2]: https://github.com/pypa/pip-audit/compare/v2.3.1...v2.3.2 [2.3.1]: https://github.com/pypa/pip-audit/compare/v2.3.0...v2.3.1 [2.3.0]: https://github.com/pypa/pip-audit/compare/v2.2.1...v2.3.0 [2.2.1]: https://github.com/pypa/pip-audit/compare/v2.2.0...v2.2.1 [2.2.0]: https://github.com/pypa/pip-audit/compare/v2.1.1...v2.2.0 [2.1.1]: https://github.com/pypa/pip-audit/compare/v2.1.0...v2.1.1 [2.1.0]: https://github.com/pypa/pip-audit/compare/v2.0.0...v2.1.0 [2.0.0]: https://github.com/pypa/pip-audit/compare/v1.1.2...v2.0.0 [1.1.2]: https://github.com/pypa/pip-audit/compare/v1.1.1...v1.1.2 [1.1.1]: https://github.com/pypa/pip-audit/compare/v1.1.0...v1.1.1 [1.1.0]: https://github.com/pypa/pip-audit/compare/v1.0.1...v1.1.0 [1.0.1]: https://github.com/pypa/pip-audit/compare/v1.0.0...v1.0.1 [1.0.0]: https://github.com/pypa/pip-audit/compare/v0.0.9...v1.0.0 [0.0.9]: https://github.com/pypa/pip-audit/compare/v0.0.8...v0.0.9
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →