feat: add uv audit to Supply Chain Security

Maintainer-proposed during the Security sitting: uv's built-in
vulnerability and malware scanning (announced 2026-06, OSV-backed,
4-10x faster than pip-audit on typical projects). Enters as a
no-signal challenger behind pip-audit — not a package, so this is a
subcommand pointer entry linking the CLI docs (httpx.URL precedent).

Astral marks the feature preview/unstable; kept by explicit maintainer
override of the production-ready quality bar — the first stability
override. The description carries the preview label.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
Vinta Chen
2026-08-16 14:15:21 +08:00
co-authored by Claude
parent fe7006edcc
commit 913b380cc8
+1
View File
@@ -1105,6 +1105,7 @@ _Frameworks and tools for penetration testing._
_Tools for auditing dependencies against known vulnerabilities._
- [pip-audit](https://github.com/pypa/pip-audit) - Audits Python environments and dependency trees for known vulnerabilities, using the PyPI Advisory Database and OSV.
- [uv audit](https://docs.astral.sh/uv/reference/cli/#uv-audit) - uv's built-in dependency vulnerability and malware scanning backed by OSV (preview).
### Web Security