audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 7b51115208

7b51115208af442930b709395937a269fffe6d95

parent: 982249b041

Unsigned

cmc <hello@cleberg.net> · 2026-08-07 02:20 UTC

Split dependencies into pyproject extras

Replace the flat requirements.txt floor (pandas + dash + plotly + boto3 +
textual for everyone) with a pyproject.toml whose core is empty and whose
optional-dependencies are grouped by capability: analysis, dashboards, aws,
collectors, mongo, tui, all, dev. A locked-down auditing laptop now installs
only what a given procedure needs.

requirements.txt is kept as a documented full-install pointer (.[all]); the
sampling, tui, aws, and root READMEs point at the targeted extra.

Layout: unified · split

README.org +11 −1
@@ -43,10 +43,20 @@ cd audit-tools
4343
4444*Install Dependencies*
4545
46Dependencies are optional /extras/, so you install only what a procedure needs
47(a locked-down laptop never has to pull pandas/dash/plotly it won't run):
48
4649#+begin_src bash
47pip install -r requirements.txt
50pip install ".[analysis]" # sampling + data analysis (pandas, Excel)
51pip install ".[aws]" # AWS collectors (boto3)
52pip install ".[collectors]" # GitHub / GitLab collectors (requests)
53pip install ".[dashboards]" # dash + plotly dashboards
54pip install ".[tui]" # the terminal UI runner
55pip install ".[all]" # everything
4856#+end_src
4957
58=~pip install -r requirements.txt~= still works and installs everything.
59
5060*Run a Script*
5161
5262For example, to run the Linux OS report tool:
applications/aws/README.md +2 −2
@@ -25,8 +25,8 @@ export AWS_AUDIT_ACCOUNT=my-account # optional; only for the SSO check
2525
2626If you authenticate with `aws login` / IAM Identity Center (SSO), those
2727credentials use the AWS Common Runtime provider, which needs the `crt` extra.
28It is included via `botocore[crt]` in `requirements.txt`; if you installed
29boto3 separately, run `pip install "botocore[crt]"`. Without it you'll see
28It is included via `botocore[crt]` in the `aws` extra (`pip install ".[aws]"`);
29if you installed boto3 separately, run `pip install "botocore[crt]"`. Without it you'll see
3030`MissingDependencyException: ... requires an additional dependency`.
3131
3232## Usage
pyproject.toml added +46
@@ -0,0 +1,46 @@
1[build-system]
2requires = ["setuptools>=77"]
3build-backend = "setuptools.build_meta"
4
5[project]
6name = "audit-tools"
7version = "0.1.0"
8description = "Scripts for programmatically gathering IT audit evidence from cloud, source control, databases, and operating systems."
9readme = { file = "README.org", content-type = "text/plain" }
10requires-python = ">=3.10"
11license = "GPL-3.0-or-later"
12authors = [{ name = "Christian Cleberg", email = "hello@cleberg.net" }]
13keywords = ["audit", "compliance", "evidence", "ITGC", "SOC2", "ISO27001"]
14
15# The core is deliberately empty: many collectors are shell scripts or use only
16# the standard library. Install just the extras a given procedure needs, so a
17# locked-down auditing laptop never pulls pandas/dash/plotly it will not run.
18dependencies = []
19
20[project.optional-dependencies]
21# Sampling and data analysis (CSV + Excel wrangling).
22analysis = ["pandas", "openpyxl", "xlrd", "PyYAML"]
23# Interactive dashboards for project / findings data.
24dashboards = ["dash", "plotly", "Werkzeug>=3.1.8"]
25# AWS evidence collectors.
26aws = ["boto3", "botocore[crt]", "urllib3>=2.7.0"]
27# GitHub / GitLab REST collectors.
28collectors = ["requests", "urllib3>=2.7.0"]
29# MongoDB user / access collectors.
30mongo = ["pymongo"]
31# Terminal UI that drives the collectors.
32tui = ["audit-tools[aws,collectors]", "textual"]
33# Everything, for a full local install.
34all = ["audit-tools[analysis,dashboards,aws,collectors,mongo,tui]"]
35# Development: linting and tests.
36dev = ["audit-tools[all]", "pytest", "ruff"]
37
38[project.urls]
39Homepage = "https://audit-labs.dev"
40Repository = "https://github.com/audit-labs/audit-tools"
41
42# This repo is a runnable script collection, not an importable library. Declare
43# no modules so `pip install .` provisions dependencies (via extras) without
44# trying to package the top-level scripts.
45[tool.setuptools]
46py-modules = []
requirements.txt +14 −13
@@ -1,13 +1,14 @@
1pandas
2openpyxl
3xlrd
4PyYAML
5pytest
6requests
7boto3
8botocore[crt]
9textual
10dash
11plotly
12urllib3>=2.7.0
13Werkzeug>=3.1.8
1# Dependencies are declared in pyproject.toml as optional "extras", so you only
2# install what a given procedure needs. Installing this file pulls EVERYTHING.
3#
4# Lighter, targeted installs (run from the repo root):
5# pip install ".[analysis]" # sampling + data analysis (pandas, Excel)
6# pip install ".[dashboards]" # dash + plotly dashboards
7# pip install ".[aws]" # AWS collectors (boto3)
8# pip install ".[collectors]" # GitHub / GitLab collectors (requests)
9# pip install ".[mongo]" # MongoDB collectors (pymongo)
10# pip install ".[tui]" # the terminal UI runner
11# pip install ".[dev]" # everything + pytest + ruff
12#
13# Full install (all optional features):
14.[all]
sampling/README.md +2 −2
@@ -13,10 +13,10 @@ audit workpaper package.
1313
1414## Installation
1515
16Install the repository requirements:
16Sampling needs only the `analysis` extra (pandas + Excel support):
1717
1818```bash
19pip install -r requirements.txt
19pip install ".[analysis]"
2020```
2121
2222Supported input formats are `.csv`, `.xlsx`, `.xls`, and `.xlsm`.
tui/README.md +1 −1
@@ -15,7 +15,7 @@ platform-agnostic.
1515## Run it
1616
1717```bash
18pip install -r requirements.txt
18pip install ".[tui]" # textual + the AWS/GitHub/GitLab collector deps
1919python audit_tui.py
2020```
2121