Introducing the Pixi Audit Beta
10 hours ago
- Pixi audit is a beta vulnerability auditing tool for conda-forge, similar to pip audit and npm audit.
- Conda-forge lacked a vulnerability database, leading to the creation of Basilisk, a dedicated database.
- Installation is done via 'pixi global install' from the prefix-labs channel, and usage involves running 'pixi audit' in a workspace or on a lock file.
- Results show vulnerabilities with severity, status, and prioritization scores, along with suggested next steps like automatic fixes with --fix.
- The tool can be integrated into CI pipelines with severity thresholds and supports JSON/SARIF output.
- Basilisk maps conda-forge packages to other vulnerability databases using PURL and CPE, and community help is encouraged.
- Future plans include OpenVEX support for vulnerability applicability and SBOM-based auditing for statically linked binaries.
- Feedback is welcomed via Discord, and security is a key focus for conda-forge products.