Files
composiohq__composio/.github
Alberto Schiabel 09ab074665 ci(py): add pip-audit gate for the uv lockfiles (#4394)
This PR:

- adds `py.audit.yml`, the Python counterpart of `ts.audit.yml`; there
was no dependency audit for the Python SDK until now
- exports each tracked `uv.lock` (the root workspace plus the standalone
`openai` and `claude_agent_sdk` provider projects) to pinned runtime
requirements with `uv export --frozen --no-dev`, then scans them with a
pinned `pip-audit --strict`
- runs on lockfile and manifest changes and on a weekly schedule, so
advisories that land without a commit still surface
- ignores the four chromadb advisories with a comment: chromadb has no
patched release, crewai pins `chromadb~=1.1.0`, and all four affect the
Chroma server that `composio-crewai` never starts
- with those ignores the gate is green on `next` today, which I verified
locally by running the exact workflow commands
2026-09-09 16:03:44 +02:00
..