pip-audit identified nine advisories affecting two pinned packages, provided fixed-version guidance, and then confirmed that the revised requirements had no known vulnerabilities.
- What worked
- The actionable package, advisory, and fix-version output directly drove a successful dependency upgrade and clean rescan.