🔍 Multi‑Tool Ready
Ships with pip‑audit and slots for Bandit/Semgrep—toggle what you need.
A tiny, powerful workflow to keep your Python dependencies safe—with smart issues, clean reports, and no yak‑shaving.
Ships with pip‑audit and slots for Bandit/Semgrep—toggle what you need.
Drop in the workflow—get issues, artifacts, and status without touching a line of code.
Noise‑free GitHub issues when vulnerabilities appear; auto‑close when clean.
No! It's smart—creates one issue when vulnerabilities are found, updates it with new scans, and auto-closes when everything is clean.
Yes—the workflow can be configured to fail your CI/CD pipeline when vulnerabilities are detected. Perfect for blocking deployments until security issues are fixed.
Absolutely! Works with both public and private repos. Private repos get 2,000 free GitHub Actions minutes per month.
In Actions → Artifacts (JSON/Markdown reports) and an auto-managed GitHub Issue with detailed vulnerability info and fix instructions.
Start with one command—or grab the minimal YAML and go.