From 283dc0a6326916bf4ca75ff1703895df4eee890e Mon Sep 17 00:00:00 2001 From: Travis Herbranson Date: Tue, 12 May 2026 07:52:23 -0400 Subject: [PATCH] deps: pin pip-audit to project venv via PIPAPI_PYTHON_LOCATION MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `uv run --directory pip-audit` runs the pip-audit BINARY through uv, but pip-audit's binary lives at ~/.local/share/uv/tools/pip-audit/ with its own embedded Python. When invoked without `PIPAPI_PYTHON_LOCATION`, pip-audit defaults to using the python it shipped with for its dependency resolution — so it audits ITS OWN venv (which has its own bundled pip + urllib3 versions, both currently flagged with CVEs) instead of the project's venv. pip-audit emits a stderr warning about this: pip-audit will run pip against ~/.local/share/uv/tools/pip-audit/bin/python, but you have a virtual environment loaded at /.venv. This may result in unintuitive audits, since your local environment will not be audited. You can forcefully override this behavior by setting PIPAPI_PYTHON_LOCATION to the location of your virtual environment's Python interpreter. Reproduced as a false positive on every uv project on this host — trellis-mcp and herbylab both got the identical 4 CVEs despite neither having pip or urllib3 in its dep tree. Fix: set PIPAPI_PYTHON_LOCATION to the project's .venv/bin/python when it exists. When it doesn't exist, fall back to the old behavior with a yellow warning that the audit may be inaccurate (avoids silently running `uv sync` as a side effect of validation). Co-Authored-By: Claude Opus 4.7 (1M context) --- validate/deps.sh | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/validate/deps.sh b/validate/deps.sh index 43bde26..3af3fc1 100755 --- a/validate/deps.sh +++ b/validate/deps.sh @@ -32,7 +32,21 @@ if [ -n "$has_python" ]; then if [ -n "$has_uvlock" ]; then printf " source: %s (uv project)\n" "$has_uvlock" pyproject_dir=$(dirname "$has_uvlock") - audit_cmd="uv run --directory $pyproject_dir pip-audit" + # Point pip-audit at the project's venv interpreter. Without this, + # `uv run pip-audit` ends up running the pip-audit binary from its + # own uv-tool install (~/.local/share/uv/tools/pip-audit/), and + # pip-audit then audits THAT environment instead of the project's + # — surfacing CVEs in pip-audit's own bundled pip/urllib3 as if + # they were the project's deps. See pip-audit's stderr warning + # ("you have a virtual environment loaded at /.venv ... + # your local environment will not be audited") for context. + project_venv_python="$pyproject_dir/.venv/bin/python" + if [ -x "$project_venv_python" ]; then + audit_cmd="PIPAPI_PYTHON_LOCATION=$project_venv_python uv run --directory $pyproject_dir pip-audit" + else + printf "${YELLOW}!${NC} No project venv at %s — pip-audit may report on its own bundled deps; run \`uv sync\` and retry for an accurate audit.\n" "$project_venv_python" + audit_cmd="uv run --directory $pyproject_dir pip-audit" + fi elif [ -n "$has_reqtxt" ]; then printf " source: %s (requirements file)\n" "$has_reqtxt" audit_cmd="pip-audit -r $has_reqtxt"