Commit 7b51115208
7b51115208af442930b709395937a269fffe6d95
parent: 982249b041
Unsigned
cmc <hello@cleberg.net> · 2026-08-07 02:20 UTC
Split dependencies into pyproject extras
Replace the flat requirements.txt floor (pandas + dash + plotly + boto3 +
textual for everyone) with a pyproject.toml whose core is empty and whose
optional-dependencies are grouped by capability: analysis, dashboards, aws,
collectors, mongo, tui, all, dev. A locked-down auditing laptop now installs
only what a given procedure needs.
requirements.txt is kept as a documented full-install pointer (.[all]); the
sampling, tui, aws, and root READMEs point at the targeted extra.
Layout: unified · split
README.org
+11 −1
| @@ -43,10 +43,20 @@ cd audit-tools |
| 43 | |
43 | |
| 44 | *Install Dependencies* |
44 | *Install Dependencies* |
| 45 | |
45 | |
| |
46 | Dependencies are optional /extras/, so you install only what a procedure needs |
| |
47 | (a locked-down laptop never has to pull pandas/dash/plotly it won't run): |
| |
48 | |
| 46 | #+begin_src bash |
49 | #+begin_src bash |
| 47 | pip install -r requirements.txt |
50 | pip install ".[analysis]" # sampling + data analysis (pandas, Excel) |
| |
51 | pip install ".[aws]" # AWS collectors (boto3) |
| |
52 | pip install ".[collectors]" # GitHub / GitLab collectors (requests) |
| |
53 | pip install ".[dashboards]" # dash + plotly dashboards |
| |
54 | pip install ".[tui]" # the terminal UI runner |
| |
55 | pip install ".[all]" # everything |
| 48 | #+end_src |
56 | #+end_src |
| 49 | |
57 | |
| |
58 | =~pip install -r requirements.txt~= still works and installs everything. |
| |
59 | |
| 50 | *Run a Script* |
60 | *Run a Script* |
| 51 | |
61 | |
| 52 | For example, to run the Linux OS report tool: |
62 | For example, to run the Linux OS report tool: |
applications/aws/README.md
+2 −2
| @@ -25,8 +25,8 @@ export AWS_AUDIT_ACCOUNT=my-account # optional; only for the SSO check |
| 25 | |
25 | |
| 26 | If you authenticate with `aws login` / IAM Identity Center (SSO), those |
26 | If you authenticate with `aws login` / IAM Identity Center (SSO), those |
| 27 | credentials use the AWS Common Runtime provider, which needs the `crt` extra. |
27 | credentials use the AWS Common Runtime provider, which needs the `crt` extra. |
| 28 | It is included via `botocore[crt]` in `requirements.txt`; if you installed |
28 | It is included via `botocore[crt]` in the `aws` extra (`pip install ".[aws]"`); |
| 29 | boto3 separately, run `pip install "botocore[crt]"`. Without it you'll see |
29 | if you installed boto3 separately, run `pip install "botocore[crt]"`. Without it you'll see |
| 30 | `MissingDependencyException: ... requires an additional dependency`. |
30 | `MissingDependencyException: ... requires an additional dependency`. |
| 31 | |
31 | |
| 32 | ## Usage |
32 | ## Usage |
pyproject.toml
added
+46
| @@ -0,0 +1,46 @@ |
| |
1 | [build-system] |
| |
2 | requires = ["setuptools>=77"] |
| |
3 | build-backend = "setuptools.build_meta" |
| |
4 | |
| |
5 | [project] |
| |
6 | name = "audit-tools" |
| |
7 | version = "0.1.0" |
| |
8 | description = "Scripts for programmatically gathering IT audit evidence from cloud, source control, databases, and operating systems." |
| |
9 | readme = { file = "README.org", content-type = "text/plain" } |
| |
10 | requires-python = ">=3.10" |
| |
11 | license = "GPL-3.0-or-later" |
| |
12 | authors = [{ name = "Christian Cleberg", email = "hello@cleberg.net" }] |
| |
13 | keywords = ["audit", "compliance", "evidence", "ITGC", "SOC2", "ISO27001"] |
| |
14 | |
| |
15 | # The core is deliberately empty: many collectors are shell scripts or use only |
| |
16 | # the standard library. Install just the extras a given procedure needs, so a |
| |
17 | # locked-down auditing laptop never pulls pandas/dash/plotly it will not run. |
| |
18 | dependencies = [] |
| |
19 | |
| |
20 | [project.optional-dependencies] |
| |
21 | # Sampling and data analysis (CSV + Excel wrangling). |
| |
22 | analysis = ["pandas", "openpyxl", "xlrd", "PyYAML"] |
| |
23 | # Interactive dashboards for project / findings data. |
| |
24 | dashboards = ["dash", "plotly", "Werkzeug>=3.1.8"] |
| |
25 | # AWS evidence collectors. |
| |
26 | aws = ["boto3", "botocore[crt]", "urllib3>=2.7.0"] |
| |
27 | # GitHub / GitLab REST collectors. |
| |
28 | collectors = ["requests", "urllib3>=2.7.0"] |
| |
29 | # MongoDB user / access collectors. |
| |
30 | mongo = ["pymongo"] |
| |
31 | # Terminal UI that drives the collectors. |
| |
32 | tui = ["audit-tools[aws,collectors]", "textual"] |
| |
33 | # Everything, for a full local install. |
| |
34 | all = ["audit-tools[analysis,dashboards,aws,collectors,mongo,tui]"] |
| |
35 | # Development: linting and tests. |
| |
36 | dev = ["audit-tools[all]", "pytest", "ruff"] |
| |
37 | |
| |
38 | [project.urls] |
| |
39 | Homepage = "https://audit-labs.dev" |
| |
40 | Repository = "https://github.com/audit-labs/audit-tools" |
| |
41 | |
| |
42 | # This repo is a runnable script collection, not an importable library. Declare |
| |
43 | # no modules so `pip install .` provisions dependencies (via extras) without |
| |
44 | # trying to package the top-level scripts. |
| |
45 | [tool.setuptools] |
| |
46 | py-modules = [] |
requirements.txt
+14 −13
| @@ -1,13 +1,14 @@ |
| 1 | pandas |
1 | # Dependencies are declared in pyproject.toml as optional "extras", so you only |
| 2 | openpyxl |
2 | # install what a given procedure needs. Installing this file pulls EVERYTHING. |
| 3 | xlrd |
3 | # |
| 4 | PyYAML |
4 | # Lighter, targeted installs (run from the repo root): |
| 5 | pytest |
5 | # pip install ".[analysis]" # sampling + data analysis (pandas, Excel) |
| 6 | requests |
6 | # pip install ".[dashboards]" # dash + plotly dashboards |
| 7 | boto3 |
7 | # pip install ".[aws]" # AWS collectors (boto3) |
| 8 | botocore[crt] |
8 | # pip install ".[collectors]" # GitHub / GitLab collectors (requests) |
| 9 | textual |
9 | # pip install ".[mongo]" # MongoDB collectors (pymongo) |
| 10 | dash |
10 | # pip install ".[tui]" # the terminal UI runner |
| 11 | plotly |
11 | # pip install ".[dev]" # everything + pytest + ruff |
| 12 | urllib3>=2.7.0 |
12 | # |
| 13 | Werkzeug>=3.1.8 |
13 | # Full install (all optional features): |
| |
14 | .[all] |
sampling/README.md
+2 −2
| @@ -13,10 +13,10 @@ audit workpaper package. |
| 13 | |
13 | |
| 14 | ## Installation |
14 | ## Installation |
| 15 | |
15 | |
| 16 | Install the repository requirements: |
16 | Sampling needs only the `analysis` extra (pandas + Excel support): |
| 17 | |
17 | |
| 18 | ```bash |
18 | ```bash |
| 19 | pip install -r requirements.txt |
19 | pip install ".[analysis]" |
| 20 | ``` |
20 | ``` |
| 21 | |
21 | |
| 22 | Supported input formats are `.csv`, `.xlsx`, `.xls`, and `.xlsm`. |
22 | Supported input formats are `.csv`, `.xlsx`, `.xls`, and `.xlsm`. |
tui/README.md
+1 −1
| @@ -15,7 +15,7 @@ platform-agnostic. |
| 15 | ## Run it |
15 | ## Run it |
| 16 | |
16 | |
| 17 | ```bash |
17 | ```bash |
| 18 | pip install -r requirements.txt |
18 | pip install ".[tui]" # textual + the AWS/GitHub/GitLab collector deps |
| 19 | python audit_tui.py |
19 | python audit_tui.py |
| 20 | ``` |
20 | ``` |
| 21 | |
21 | |