Skip to content

Commit 454d956

Browse files
committed
README: prep for 1.0.3
Signed-off-by: William Woodruff <william@trailofbits.com>
1 parent e02369a commit 454d956

File tree

1 file changed

+20
-20
lines changed

1 file changed

+20
-20
lines changed

README.md

+20-20
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ jobs:
3232
- uses: actions/checkout@v3
3333
- name: install
3434
run: python -m pip install .
35-
- uses: pypa/gh-action-pip-audit@v1.0.2
35+
- uses: pypa/gh-action-pip-audit@v1.0.3
3636
```
3737
3838
Or, with a virtual environment:
@@ -48,7 +48,7 @@ jobs:
4848
python -m venv env/
4949
source env/bin/activate
5050
python -m pip install .
51-
- uses: pypa/gh-action-pip-audit@v1.0.2
51+
- uses: pypa/gh-action-pip-audit@v1.0.3
5252
with:
5353
virtual-environment: env/
5454
```
@@ -72,15 +72,15 @@ The `inputs` setting controls what sources `pip-audit` runs on.
7272
To audit one or more requirements-style inputs:
7373

7474
```yaml
75-
- uses: pypa/gh-action-pip-audit@v1.0.2
75+
- uses: pypa/gh-action-pip-audit@v1.0.3
7676
with:
7777
inputs: requirements.txt dev-requirements.txt
7878
```
7979

8080
To audit a project that uses `pyproject.toml` for its dependencies:
8181

8282
```yaml
83-
- uses: pypa/gh-action-pip-audit@v1.0.2
83+
- uses: pypa/gh-action-pip-audit@v1.0.3
8484
with:
8585
# NOTE: this can be `.`, for the current directory
8686
inputs: path/to/project/
@@ -108,7 +108,7 @@ Example: use the virtual environment specified at `env/`, relative to the
108108
current directory:
109109

110110
```yaml
111-
- uses: pypa/gh-action-pip-audit@v1.0.2
111+
- uses: pypa/gh-action-pip-audit@v1.0.3
112112
with:
113113
virtual-environment: env/
114114
# Note the absence of `input:`, since we're auditing the environment.
@@ -128,7 +128,7 @@ installed directly into the current environment are included.
128128
Example:
129129

130130
```yaml
131-
- uses: pypa/gh-action-pip-audit@v1.0.2
131+
- uses: pypa/gh-action-pip-audit@v1.0.3
132132
with:
133133
local: true
134134
```
@@ -145,7 +145,7 @@ It's directly equivalent to `pip-audit --vulnerability-service=...`.
145145
To audit with OSV instead of PyPI:
146146

147147
```yaml
148-
- uses: pypa/gh-action-pip-audit@v1.0.2
148+
- uses: pypa/gh-action-pip-audit@v1.0.3
149149
with:
150150
vulnerability-service: osv
151151
```
@@ -160,7 +160,7 @@ It's directly equivalent to `pip-audit --require-hashes ...`.
160160
Example:
161161

162162
```yaml
163-
- uses: pypa/gh-action-pip-audit@v1.0.2
163+
- uses: pypa/gh-action-pip-audit@v1.0.3
164164
with:
165165
# NOTE: only works with requirements-style inputs
166166
inputs: requirements.txt
@@ -177,7 +177,7 @@ It's directly equivalent to `pip-audit --no-deps ...`.
177177
Example:
178178

179179
```yaml
180-
- uses: pypa/gh-action-pip-audit@v1.0.2
180+
- uses: pypa/gh-action-pip-audit@v1.0.3
181181
with:
182182
# NOTE: only works with requirements-style inputs
183183
inputs: requirements.txt
@@ -195,7 +195,7 @@ is rendered at the end of the action.
195195
Example:
196196

197197
```yaml
198-
- uses: pypa/gh-action-pip-audit@v1.0.2
198+
- uses: pypa/gh-action-pip-audit@v1.0.3
199199
with:
200200
summary: false
201201
```
@@ -214,7 +214,7 @@ indices to search (such as a corporate index with private packages), see
214214
Example:
215215

216216
```yaml
217-
- uses: pypa/gh-action-pip-audit@v1.0.2
217+
- uses: pypa/gh-action-pip-audit@v1.0.3
218218
with:
219219
index-url: https://example.corporate.local/simple
220220
```
@@ -229,7 +229,7 @@ indexes to search when resolving dependencies. Each URL is whitespace-separated.
229229
Example:
230230

231231
```yaml
232-
- uses: pypa/gh-action-pip-audit@v1.0.2
232+
- uses: pypa/gh-action-pip-audit@v1.0.3
233233
with:
234234
extra-index-urls: |
235235
https://example.corporate.local/simple
@@ -246,7 +246,7 @@ ignore (i.e., exclude from the results) if present. Each ID is whitespace-separa
246246
Example
247247

248248
```yaml
249-
- uses: pypa/gh-action-pip-audit@v1.0.2
249+
- uses: pypa/gh-action-pip-audit@v1.0.3
250250
with:
251251
ignore-vulns: |
252252
GHSA-XXXX-YYYYYY
@@ -276,7 +276,7 @@ Example
276276
Example:
277277

278278
```yaml
279-
- uses: pypa/gh-action-pip-audit@v1.0.2
279+
- uses: pypa/gh-action-pip-audit@v1.0.3
280280
with:
281281
internal-be-careful-allow-failure: true
282282
```
@@ -295,7 +295,7 @@ Example
295295
Example:
296296

297297
```yaml
298-
- uses: pypa/gh-action-pip-audit@v1.0.2
298+
- uses: pypa/gh-action-pip-audit@v1.0.3
299299
with:
300300
internal-be-careful-debug: true
301301
```
@@ -312,7 +312,7 @@ If you're auditing a requirements file, consider setting `no-deps: true` or
312312
`require-hashes: true`:
313313

314314
```yaml
315-
- uses: pypa/gh-action-pip-audit@v1.0.2
315+
- uses: pypa/gh-action-pip-audit@v1.0.3
316316
with:
317317
inputs: requirements.txt
318318
require-hashes: true
@@ -321,7 +321,7 @@ If you're auditing a requirements file, consider setting `no-deps: true` or
321321
or:
322322

323323
```yaml
324-
- uses: pypa/gh-action-pip-audit@v1.0.2
324+
- uses: pypa/gh-action-pip-audit@v1.0.3
325325
with:
326326
inputs: requirements.txt
327327
no-deps: true
@@ -342,7 +342,7 @@ by the host system itself, or other Python projects that happen to be installed.
342342
To minimize external dependencies, you can opt into a virtual environment:
343343

344344
```yaml
345-
- uses: pypa/gh-action-pip-audit@v1.0.2
345+
- uses: pypa/gh-action-pip-audit@v1.0.3
346346
with:
347347
# must be populated earlier in the CI
348348
virtual-environment: env/
@@ -352,7 +352,7 @@ and, more aggressively, specify that only dependencies marked as "local"
352352
in the virtual environment should be included:
353353

354354
```yaml
355-
- uses: pypa/gh-action-pip-audit@v1.0.2
355+
- uses: pypa/gh-action-pip-audit@v1.0.3
356356
with:
357357
# must be populated earlier in the CI
358358
virtual-environment: env/
@@ -382,7 +382,7 @@ jobs:
382382
run: |
383383
pipx run pipfile-requirements Pipfile.lock > requirements.txt
384384
385-
- uses: pypa/gh-action-pip-audit@v1.0.2
385+
- uses: pypa/gh-action-pip-audit@v1.0.3
386386
with:
387387
inputs: requirements.txt
388388
```

0 commit comments

Comments
 (0)