Pixi Audit Beta is a new vulnerability-auditing tool for pixi workspaces that targets conda-forge and PyPI packages, built to fill the gap left by the lack of a dedicated conda-forge vulnerability database. It inspects lock files (or entire workspaces) and reports matches with severity and remediation status; an example audit flagged 110 packages and 260 vulnerability matches (9 critical, 89 high, 101 medium, 26 low, 35 unknown), with 120 vulnerabilities having fixes available within the audited ecosystem, 35 fixed only upstream, and 105 with no known fix. The tool produces a prioritized assessment, human-readable findings, and suggested next steps, and can automatically attempt safe fixes by bumping direct dependency versions while preserving constraints; transitive, unversioned, and VCS/path/URL dependencies are left unchanged.
The audit integrates into CI with configurable failure thresholds and outputs JSON/SARIF for tooling. Underlying the tool is Basilisk, a new conda-forge vulnerability database plus a purl-associator that maps conda-forge packages to other ecosystems (using PURL and CPE) so advisories from sources like OSV/NVD can be linked. Future work includes OpenVEX support to mark vulnerabilities as not applicable and using per-package SBOMs to detect statically bundled or transitive binary vulnerabilities. Users are invited to test pixi audit, contribute identity mappings, and report mismatches or workflow concerns.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.