$npx skillfedfor your agent

uv-secure

Deprecated dependency scanner for uv projects; use uv audit instead

SkipPyPI LibrariesReleased Apr 2026164.3K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — uv_secure-0.17.2-py3-none-any.whl
v0.17.2 · released 2026-04-18 · Python >=3.10 · 13 runtime deps: anyio, cvss, httpx, humanize, inflect, orjson, packaging, pydantic

No. The package is abandoned and explicitly deprecated in favor of `uv audit`, which is now the standard for uv projects. Install uv-secure only if you have a legacy workflow that `uv audit` does not support; otherwise, use the built-in command or consider pip-audit or pysentry-rs instead.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python >=3.10 and network access to PyPI API; only works with PyPI-sourced packages, not private or custom package repositories.
  • Low install friction with 13 runtime dependencies.
  • However, the package is abandoned (last commit 2026-04-18, repository archived) and explicitly deprecated in favor of the built-in `uv audit` command, which should be preferred for new projects.

License · maintenance · safety

MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions, making it legally straightforward to adopt—though the deprecation status makes this less relevant.

last release 2026-04-18 (118 days) · last repo commit 2026-04-18 · 146 stars · archived

0 known vulnerabilities (OSV.dev, 2026-08-14) · 164,291 downloads/mo, #10,554 on PyPI

Verify before relying

uv tool install uv-secure
uv-secure path/to/uv.lock
# or: uv-secure --help for full options
  • Whether the tool's alpha-phase command-line interface remains stable or may change without deprecation warning.
  • Performance impact of network requests for each PyPI package in large lock files.
  • Compatibility with the latest uv versions and whether `uv audit` now covers all uv-secure use cases.
Same gist for agents: .md · .json

What it is and what it does

uv-secure is a deprecated CLI tool that scans dependency lock files (uv.lock, pylock.toml, requirements.txt) for known security vulnerabilities by querying PyPI metadata. It was created to bridge gaps with pip-audit integration for uv projects but is now superseded by the native `uv audit` command. The tool makes concurrent network requests to PyPI for each dependency, caches responses (default TTL 86400 seconds), and reports vulnerabilities with optional severity, aliases, and descriptions. It also checks the versions of the globally installed uv CLI and uv-secure itself for vulnerabilities.

The package depends on 13 runtime libraries including httpx for HTTP requests, pydantic for validation, rich for terminal output, and typer for CLI scaffolding. It is explicitly marked as abandoned and in alpha phase, meaning command-line arguments may change without notice. The author recommends using `uv audit` for new projects, or pip-audit and pysentry-rs as alternatives if uv audit does not fit your workflow.

Use it for

  • Audit PyPI dependencies in uv.lock files before deployment in CI/CD pipelines.
  • Check requirements.txt files for known vulnerabilities in projects not yet migrated to uv.
  • Scan PEP 751 pylock.toml files for security issues in lock-file-based workflows.
  • Monitor the security status of the uv tool itself and uv-secure package versions.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No.

The package is abandoned and explicitly deprecated in favor of `uv audit`, which is now the standard for uv projects. Install uv-secure only if you have a legacy workflow that `uv audit` does not support; otherwise, use the built-in command or consider pip-audit or pysentry-rs instead.

Install

uv-secure on PyPI

Before you install

Low install friction with 13 runtime dependencies. However, the package is abandoned (last commit 2026-04-18, repository archived) and explicitly deprecated in favor of the built-in `uv audit` command, which should be preferred for new projects.

Requires Python >=3.10 and network access to PyPI API; only works with PyPI-sourced packages, not private or custom package repositories.

License in practice

MIT license permits free use, modification, and distribution with minimal restrictions, making it legally straightforward to adopt—though the deprecation status makes this less relevant.

Quickstart

uv tool install uv-secure
uv-secure path/to/uv.lock
# or: uv-secure --help for full options

Verify before relying

  • Whether the tool's alpha-phase command-line interface remains stable or may change without deprecation warning.
  • Performance impact of network requests for each PyPI package in large lock files.
  • Compatibility with the latest uv versions and whether `uv audit` now covers all uv-secure use cases.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
13 packages
anyiocvsshttpxhumanizeinflectorjsonpackagingpydanticrichstaminatomlitomlkittyper
MaintenanceAbandoned 118 days since the last release
Last repo commit repository archived
First released
Downloads164,291 / month, #10,554 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 7 - InactiveEnvironment :: ConsoleIntended Audience :: DevelopersNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Software Development :: LibrariesTopic :: Software Development :: Quality AssuranceTopic :: Software Development :: Testing

Evidence: uv_secure-0.17.2-py3-none-any.whl

Tags

Capabilities
uv dependency vulnerability scannercheck uv.lock for security issuespypi vulnerability auditingdependency security scanninguv project security auditvulnerability detection uvpypi package vulnerability checker
Topics
deprecatedvulnerability-scanninguv-ecosystem
PyPI keywords
uvuv.lockvulnerabilities

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “uv dependency vulnerability scanner”

  • uv-secureScans uv.lock, pylock.toml, and requirements.txt files for known…
  • pysentry-rsPySentry scans Python projects for known security vulnerabilities by…
  • pip-auditpip-audit scans Python environments and requirements files for…

Give your agent the search over MCP, or paste the wish link into any chat.

More Libraries packages

urllib3 Worth it
PyPI · Libraries · released May 2026

urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.

MITpure Python · 3.10+
1.8Bdownloads / mo
requests Worth it
PyPI · Libraries · released May 2026

Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.

Apache-2.0pure Python · 3.10+
1.8Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
python-dateutil Worth it
PyPI · Libraries · released Mar 2024

Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.

Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.

Apache-2.0pure Python
1.2Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo
pytest Worth it
PyPI · Libraries · released Jun 2026

pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.

MITpure Python · 3.10+
1.1Bdownloads / mo

See also depgather · pip-audit · pysentry-rs · safety · liccheck · zaproxy · nvdlib · debsecan-mcp · python-gvm · poetry-plugin-export