pip-audit has unhealthy dependencies
envgap__pypa__pip-audit-203
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
2691389a792c9b77968b365d70b85218acfe8eba- Manifest
setup.py- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
pypa/pip-audit #203 · read the original issue
## Bug description Running [Deadpendency](https://deadpendency.com) on pip-audit results in three unhealthy pip-audit (direct/indirect) dependencies: - lockfile – 📦 - ❌ Last package release over 24 months ago. Last release: 2015-11-25 - ⚠ A source repository was not identified. - requirements-parser – 📖 📦 - ❌ No commits within the last 18 months. Last commit: 2020-03-31 - ❌ Last package release over 24 months ago. Last release: 2018-01-12 - webencodings – 📖 📦 - ❌ No commits within the last 18 months. - ❌ Last package release over 24 months ago. Last release: 2017-04-05 ## Reproduction steps [Install Deadpendency](https://deadpendency.com/docs/getting-started#installation) on a public GitHub repo that has pip-audit in its requirements.txt. An example Deadpendency report (including the dependencies listed above) can be found here: https://github.com/ICTU/quality-time/pull/3021/checks?check_run_id=4501775840 ## Expected behavior pip-audit shouldn't rely on unhealthy dependencies. ## Platform information * OS name and version: n/a * `pip-audit` version (`pip-audit -V`): pip-audit 1.1.1 * Python version (`python -V` or `python3 -V`): Python 3.10.0 * `pip` version (`pip -V` or `pip3 -V`): pip 21.3.1
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]