Skip to content

Commit 90892b3

Browse files
committed
Remove running pip-audit from CI.
pip has had a recent CVE, and as a library (and not an app) it is difficult to run pip-audit in a way that has value but is segregated from pip-audit's own deps such that we don't encounter this kind of false positive.
1 parent 4fd4510 commit 90892b3

File tree

1 file changed

+0
-9
lines changed

1 file changed

+0
-9
lines changed

noxfile.py

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -63,15 +63,6 @@ def tests(session):
6363
session.run("pytest", *session.posargs, PACKAGE)
6464

6565

66-
@session(python=SUPPORTED)
67-
def audit(session):
68-
"""
69-
Audit Python dependencies for vulnerabilities.
70-
"""
71-
session.install("pip-audit", ROOT)
72-
session.run("python", "-m", "pip_audit")
73-
74-
7566
@session(tags=["build"])
7667
def build(session):
7768
"""

0 commit comments

Comments
 (0)