# Towards a \`pip audit\` subcommand for vulnerability analysis & management

**URL:** <https://discuss.python.org/t/towards-a-pip-audit-subcommand-for-vulnerability-analysis-management/17681>\
**Category:** Packaging\
**Created:** [July 25, 2022, 8:53pm UTC](https://discuss.python.org/t/towards-a-pip-audit-subcommand-for-vulnerability-analysis-management/17681 "2022-07-25T20:53:00Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![pf\_moore](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/pf_moore/32/35_2.png) [@pf\_moore](https://discuss.python.org/u/pf_moore)\
**Post date:** [July 26, 2022, 11:27pm UTC](https://discuss.python.org/t/towards-a-pip-audit-subcommand-for-vulnerability-analysis-management/17681/9 "2022-07-26T23:27:07Z")

</div>

> [@dustin](#):
>
> I kind of addressed this in OP, but the main reason is that we want to make this “canonical and easily available to every Python user”.

Thanks. To be honest, I don’t really have much sympathy for the “we want it to be available to all Python users, so bung it in pip” argument. That’s very much a personal view, so the other pip maintainers may disagree, but I think pip is _already_ overloaded with functionality and we should be streamlining, not adding more.

In particular, the whole point of pip is to make using other packages seamless and straightforward. What about `pip install pip-audit` is too much to expect people to do? That’s a genuine question, I suspect I have an idea of what you’ll say but I’d like to be explicit - my suspicion is that “putting it in pip” is an attempt to apply a technical solution (“you don’t have to install it”) to a social problem (people don’t want to bother with audits unless they are told to, and will grab at excuses like “it’s not installed” if they can). If there _is_ a technical reason why `pip install pip-audit` is a problem, maybe we should solve _that_ problem for the general case, rather than avoiding it just for this one package.

A tool like black seems to have managed to become ubiquitous without being a pip subcommand. Why can’t `pip-audit`?

---

_[View the full topic](https://discuss.python.org/t/towards-a-pip-audit-subcommand-for-vulnerability-analysis-management/17681)._
