Replies: 3 comments 4 replies
-
|
Hi @benglewis ! Is |
Beta Was this translation helpful? Give feedback.
-
|
It is very new, so it isn’t extremely popular yet, but it is the best solution for the problems that it solves. There aren’t really any better solutions out there. I also imagine that those that need lock files are mostly not publishing to public GitHub repos |
Beta Was this translation helpful? Give feedback.
-
|
Commenting -- wish we had this as well |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Description
The new package manager in Python and Rust land with the name
pixiis really fast, convenient (it has the optional to create feature sections, platform-specific dependencies and different environments, which can share dependency feature blocks, as well as automatic lock file maintenance, and most importantly, for us, support both for PyPI packages as well as Conda packages fromconda-forgeand other repositories likenvidiaandpytorch).Since it uses a different lock file than the existing packages, I believe that Trivy will not work as currently built. I may be wrong and I would be happy to discover that.
We are currently using SafetyCLI to scan the
pyproject.tomlfor regular PyPI packages andjaketo scan our Conda packages usingmicromambato get the list of the package versions - yes it is a bit ugly.Target
Git Repository
Scanner
Vulnerability
Beta Was this translation helpful? Give feedback.
All reactions