"""Adapter: pip-audit -f json normalized to Finding[]. Findings are attached to the dependency manifest file rather than a source file, since the vulnerability is in a pinned dep, not in code. """ from __future__ import annotations import json from scripts.manifest import Finding def parse_pip_audit_output(stdout: str, manifest_path: str = "requirements.txt") -> list[Finding]: try: payload = json.loads(stdout) except json.JSONDecodeError: return [] out: list[Finding] = [] for dep in payload.get("dependencies", []): name = dep.get("name", "") version = dep.get("version", "") for v in dep.get("vulns", []): fix = v.get("fix_versions") or [] fix_str = ", ".join(fix) if fix else None out.append(Finding( tool="pip-audit", rule_id=v.get("id", ""), severity="high", file=manifest_path, line=1, end_line=1, message=f"{name} {version}: {v.get('description', '')}", fix_suggestion=f"upgrade to {fix_str}" if fix_str else None, )) return out