From 5268e5834bdd9a1e6cfacb1dc33f99dbf2fb70d1 Mon Sep 17 00:00:00 2001 From: Marco D'Aleo Date: Thu, 25 Dec 2025 10:28:46 +0000 Subject: [PATCH] Make pip-audit run inside Poetry --- .gitea/workflows/lint-and-security.yml | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/lint-and-security.yml b/.gitea/workflows/lint-and-security.yml index b74bef1..fa95502 100644 --- a/.gitea/workflows/lint-and-security.yml +++ b/.gitea/workflows/lint-and-security.yml @@ -22,8 +22,15 @@ jobs: - name: Run pre-commit hooks run: pre-commit run --all-files --color always + - name: Install Poetry + run: | + pip install poetry + poetry self add poetry-plugin-export + - name: Install pip-audit run: pip install pip-audit - - name: Run pip-audit - run: pip-audit + - name: Audit dependencies (Poetry lockfile) + run: | + poetry export -f requirements.txt --without-hashes \ + | pip-audit -r /dev/stdin -- 2.49.1