boredchilada/piptastic
Its not fantastic, its piptastic - Dependency auditor for Python projects: drift vs PyPI, known CVEs via pip-audit, minimum safe versions, and CVE-aware update rewriting. Walks one project or a whole tree. JSON, SARIF for GitHub Code Scanning, and CI exit-code gates.
GitHub repository with 6 stars and 1 forks.
Language: Python
Topics: agpl, cli, cve, dependency-management, devsecops, pip, pip-audit, python, security, supply-chain-security