Skip to content

Replace Safety with uv audit in security checks - #29

Closed
dbritto-dev with Copilot wants to merge 2 commits into
dependabot/pip/safety-3.8.1from
copilot/fix-security-checks
Closed

dbritto-dev with Copilot wants to merge 2 commits into
dependabot/pip/safety-3.8.1from
copilot/fix-security-checks

Conversation

Copilot AI commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

The Python 3.10 security job fails when Safety’s HTTP client raises a TypeError while fetching authentication metadata. Replace the dependency scan with uv’s native audit.

  • Changes
    • Keep Bandit and run uv audit --locked for dependency checks.
    • Remove Safety and its setuptools workaround; update the lockfile, CI label, and security docs.
uv audit --locked

Copilot AI and others added 2 commits October 7, 2026 03:37
Co-authored-by: dbritto-dev <1697714+dbritto-dev@users.noreply.github.com>
Co-authored-by: dbritto-dev <1697714+dbritto-dev@users.noreply.github.com>
@dbritto-dev
dbritto-dev added this pull request to stack #30 October 7, 2026 03:42
@dependabot
dependabot Bot deleted the branch dependabot/pip/safety-3.8.1 October 7, 2026 03:43
@dependabot dependabot Bot closed this Oct 7, 2026
@dbritto-dev
dbritto-dev deleted the copilot/fix-security-checks branch October 7, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants