← All tasks
pythonpypa/pip-audit #203Not a task: already works

pip-audit has unhealthy dependencies

envgap__pypa__pip-audit-203

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
2691389a792c9b77968b365d70b85218acfe8eba
Manifest
setup.py
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

pypa/pip-audit #203 · read the original issue
## Bug description



Running [Deadpendency](https://deadpendency.com) on pip-audit results in three unhealthy pip-audit (direct/indirect) dependencies:



- lockfile – 📦

  - ❌ Last package release over 24 months ago. Last release: 2015-11-25

  - ⚠ A source repository was not identified.

- requirements-parser – 📖 📦

  - ❌ No commits within the last 18 months. Last commit: 2020-03-31

  - ❌ Last package release over 24 months ago. Last release: 2018-01-12

- webencodings – 📖 📦

  - ❌ No commits within the last 18 months.

  - ❌ Last package release over 24 months ago. Last release: 2017-04-05



## Reproduction steps 



[Install Deadpendency](https://deadpendency.com/docs/getting-started#installation) on a public GitHub repo that has pip-audit in its requirements.txt. 



An example Deadpendency report (including the dependencies listed above) can be found here: https://github.com/ICTU/quality-time/pull/3021/checks?check_run_id=4501775840



## Expected behavior



pip-audit shouldn't rely on unhealthy dependencies.



## Platform information



* OS name and version: n/a

* `pip-audit` version (`pip-audit -V`): pip-audit 1.1.1

* Python version (`python -V` or `python3 -V`): Python 3.10.0

* `pip` version (`pip -V` or `pip3 -V`): pip 21.3.1

Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]