Repository navigation
fix!: fail closed when pip-audit cannot run; reject package_manager pip - #85
Merged
Merged
Conversation
A failed uv/poetry/pipenv export, a missing requirements file or a pip-audit crash (exit 1, the same code as "vulnerabilities found") was reported as "No vulnerabilities found" with exit 0. Any run without a pip-audit JSON report now exits non-zero and writes "pip-audit did NOT run" to the step summary. - uv export drops the caller's project (--no-emit-project), and pinned exports (uv, poetry, pipenv) are audited with --disable-pip, so pip-audit no longer builds the project in a venv (--no-deps was a no-op without it). requirements mode keeps pip resolution. - pipenv without Pipfile.lock fails instead of auditing an empty list. - package_manager pip ran `pip freeze` inside the action's own uv environment, so it audited the action's dependencies, not the caller's. It now fails with a pointer to requirements mode. - validate_results.py errors when a pip-audit case has no report or audited zero dependencies. Refs #84 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
✅ All test workflows behaved as expected13 passed, 0 failed
|
The Pipfile.lock check only looked in the current directory. pipenv keeps the lock at <Pipfile>.lock, so it now honours PIPENV_PIPFILE. The lock check and the executable lookup now run before the temp requirements file is created, and a failed export deletes that file. Refs #84 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…udits When pip-audit could not run, the action exited before it wrote the bandit section, emitted annotations or updated the PR comment. A red job could then sit next to a stale "all clean" comment. It now renders the whole report with a "pip-audit did NOT run" section, emits an ::error:: annotation with the reason, updates the comment and then exits non-zero. A pip-audit-report.json left by an earlier run is deleted first, so the always() upload never publishes stale results. A valid report that audited zero dependencies, or skipped all of them, no longer says "No vulnerabilities found". The section shows the audited and skipped counts, and a ::warning:: is emitted when nothing was audited. Such a run does not fail: a project with no dependencies is legitimate. Refs #84 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
It had no callers, and its pip_stdout="[]" default is no longer a valid pip-audit report. The clean-audit mock now reports one audited dependency, as a real clean run does. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
lhoupert/bandit-action e2d4893 is 18022d5 minus its "Checkout repository" step. That nested actions/checkout ran with clean: true (git clean -ffdx and git reset --hard) in the caller's workspace. It deleted lockfiles the caller generated before this action (integration cases 04, 07 and 10), and it reverted the `uv lock --upgrade` in ci.yml's self-audit before pip-audit ran. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
| if: contains(inputs.tools, 'bandit') | ||
| continue-on-error: true | ||
| uses: lhoupert/bandit-action@18022d5292d04b21fae1bfa44597b94402ba7365 | ||
| uses: lhoupert/bandit-action@e2d48932beda5cc8c50cb45ed39f8d873ef2d365 |
1 task done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When pip-audit could not run, the action reported "✅ No vulnerabilities found" and exited 0, and
package_manager: pipaudited the action's own environment. "Could not run" covers a failed export, a missing requirements file or a crash, because pip-audit uses exit 1 for both crashes and findings. Now:--no-emit-project,--disable-pip);pipmode fails with a pointer torequirementsmode;Fixes #84.
For reviewers: setups that were never really audited now turn red. Examples are default inputs with no
requirements.txt, pipenv without aPipfile.lock, and locks with fixable CVEs that were never reported.Author attestation
AI-assisted: Claude Code wrote the change, the tests and the local end-to-end checks.