pip-audit: no known vulnerabilities.

Scope
[project] dependencies in pyproject.toml (not [dev] extras)
Direct requirements
packaging>=23.0, platformdirs>=4.0, tomlkit>=0.11, typer>=0.12
Resolved packages
9 (0 skipped)
Service
PyPI advisory (pip-audit default)

This is the dependency exhibit. Bandit scans our source; pip-audit asks whether the resolved runtime tree has a published advisory.