Hasty Briefsbeta

Bilingual

Introducing the Pixi Audit Beta

10 hours ago
  • Pixi audit is a beta vulnerability auditing tool for conda-forge, similar to pip audit and npm audit.
  • Conda-forge lacked a vulnerability database, leading to the creation of Basilisk, a dedicated database.
  • Installation is done via 'pixi global install' from the prefix-labs channel, and usage involves running 'pixi audit' in a workspace or on a lock file.
  • Results show vulnerabilities with severity, status, and prioritization scores, along with suggested next steps like automatic fixes with --fix.
  • The tool can be integrated into CI pipelines with severity thresholds and supports JSON/SARIF output.
  • Basilisk maps conda-forge packages to other vulnerability databases using PURL and CPE, and community help is encouraged.
  • Future plans include OpenVEX support for vulnerability applicability and SBOM-based auditing for statically linked binaries.
  • Feedback is welcomed via Discord, and security is a key focus for conda-forge products.