Commit 7b51115208
7b51115208af442930b709395937a269fffe6d95
parent: 982249b041
Unsigned
cmc <hello@cleberg.net> · 2026-08-07 02:20 UTC
Split dependencies into pyproject extras
Replace the flat requirements.txt floor (pandas + dash + plotly + boto3 +
textual for everyone) with a pyproject.toml whose core is empty and whose
optional-dependencies are grouped by capability: analysis, dashboards, aws,
collectors, mongo, tui, all, dev. A locked-down auditing laptop now installs
only what a given procedure needs.
requirements.txt is kept as a documented full-install pointer (.[all]); the
sampling, tui, aws, and root READMEs point at the targeted extra.
Layout: unified · split
README.org
+11 −1
| @@ -43,10 +43,20 @@ cd audit-tools |
| 43 | 43 | |
| 44 | 44 | *Install Dependencies* |
| 45 | 45 | |
| 46 | Dependencies are optional /extras/, so you install only what a procedure needs |
| 47 | (a locked-down laptop never has to pull pandas/dash/plotly it won't run): |
| 48 | |
| 46 | 49 | #+begin_src bash |
| 47 | | pip install -r requirements.txt |
| 50 | pip install ".[analysis]" # sampling + data analysis (pandas, Excel) |
| 51 | pip install ".[aws]" # AWS collectors (boto3) |
| 52 | pip install ".[collectors]" # GitHub / GitLab collectors (requests) |
| 53 | pip install ".[dashboards]" # dash + plotly dashboards |
| 54 | pip install ".[tui]" # the terminal UI runner |
| 55 | pip install ".[all]" # everything |
| 48 | 56 | #+end_src |
| 49 | 57 | |
| 58 | =~pip install -r requirements.txt~= still works and installs everything. |
| 59 | |
| 50 | 60 | *Run a Script* |
| 51 | 61 | |
| 52 | 62 | For example, to run the Linux OS report tool: |
applications/aws/README.md
+2 −2
| @@ -25,8 +25,8 @@ export AWS_AUDIT_ACCOUNT=my-account # optional; only for the SSO check |
| 25 | 25 | |
| 26 | 26 | If you authenticate with `aws login` / IAM Identity Center (SSO), those |
| 27 | 27 | credentials use the AWS Common Runtime provider, which needs the `crt` extra. |
| 28 | | It is included via `botocore[crt]` in `requirements.txt`; if you installed |
| 29 | | boto3 separately, run `pip install "botocore[crt]"`. Without it you'll see |
| 28 | It is included via `botocore[crt]` in the `aws` extra (`pip install ".[aws]"`); |
| 29 | if you installed boto3 separately, run `pip install "botocore[crt]"`. Without it you'll see |
| 30 | 30 | `MissingDependencyException: ... requires an additional dependency`. |
| 31 | 31 | |
| 32 | 32 | ## Usage |
pyproject.toml
added
+46
| @@ -0,0 +1,46 @@ |
| 1 | [build-system] |
| 2 | requires = ["setuptools>=77"] |
| 3 | build-backend = "setuptools.build_meta" |
| 4 | |
| 5 | [project] |
| 6 | name = "audit-tools" |
| 7 | version = "0.1.0" |
| 8 | description = "Scripts for programmatically gathering IT audit evidence from cloud, source control, databases, and operating systems." |
| 9 | readme = { file = "README.org", content-type = "text/plain" } |
| 10 | requires-python = ">=3.10" |
| 11 | license = "GPL-3.0-or-later" |
| 12 | authors = [{ name = "Christian Cleberg", email = "hello@cleberg.net" }] |
| 13 | keywords = ["audit", "compliance", "evidence", "ITGC", "SOC2", "ISO27001"] |
| 14 | |
| 15 | # The core is deliberately empty: many collectors are shell scripts or use only |
| 16 | # the standard library. Install just the extras a given procedure needs, so a |
| 17 | # locked-down auditing laptop never pulls pandas/dash/plotly it will not run. |
| 18 | dependencies = [] |
| 19 | |
| 20 | [project.optional-dependencies] |
| 21 | # Sampling and data analysis (CSV + Excel wrangling). |
| 22 | analysis = ["pandas", "openpyxl", "xlrd", "PyYAML"] |
| 23 | # Interactive dashboards for project / findings data. |
| 24 | dashboards = ["dash", "plotly", "Werkzeug>=3.1.8"] |
| 25 | # AWS evidence collectors. |
| 26 | aws = ["boto3", "botocore[crt]", "urllib3>=2.7.0"] |
| 27 | # GitHub / GitLab REST collectors. |
| 28 | collectors = ["requests", "urllib3>=2.7.0"] |
| 29 | # MongoDB user / access collectors. |
| 30 | mongo = ["pymongo"] |
| 31 | # Terminal UI that drives the collectors. |
| 32 | tui = ["audit-tools[aws,collectors]", "textual"] |
| 33 | # Everything, for a full local install. |
| 34 | all = ["audit-tools[analysis,dashboards,aws,collectors,mongo,tui]"] |
| 35 | # Development: linting and tests. |
| 36 | dev = ["audit-tools[all]", "pytest", "ruff"] |
| 37 | |
| 38 | [project.urls] |
| 39 | Homepage = "https://audit-labs.dev" |
| 40 | Repository = "https://github.com/audit-labs/audit-tools" |
| 41 | |
| 42 | # This repo is a runnable script collection, not an importable library. Declare |
| 43 | # no modules so `pip install .` provisions dependencies (via extras) without |
| 44 | # trying to package the top-level scripts. |
| 45 | [tool.setuptools] |
| 46 | py-modules = [] |
requirements.txt
+14 −13
| @@ -1,13 +1,14 @@ |
| 1 | | pandas |
| 2 | | openpyxl |
| 3 | | xlrd |
| 4 | | PyYAML |
| 5 | | pytest |
| 6 | | requests |
| 7 | | boto3 |
| 8 | | botocore[crt] |
| 9 | | textual |
| 10 | | dash |
| 11 | | plotly |
| 12 | | urllib3>=2.7.0 |
| 13 | | Werkzeug>=3.1.8 |
| 1 | # Dependencies are declared in pyproject.toml as optional "extras", so you only |
| 2 | # install what a given procedure needs. Installing this file pulls EVERYTHING. |
| 3 | # |
| 4 | # Lighter, targeted installs (run from the repo root): |
| 5 | # pip install ".[analysis]" # sampling + data analysis (pandas, Excel) |
| 6 | # pip install ".[dashboards]" # dash + plotly dashboards |
| 7 | # pip install ".[aws]" # AWS collectors (boto3) |
| 8 | # pip install ".[collectors]" # GitHub / GitLab collectors (requests) |
| 9 | # pip install ".[mongo]" # MongoDB collectors (pymongo) |
| 10 | # pip install ".[tui]" # the terminal UI runner |
| 11 | # pip install ".[dev]" # everything + pytest + ruff |
| 12 | # |
| 13 | # Full install (all optional features): |
| 14 | .[all] |
sampling/README.md
+2 −2
| @@ -13,10 +13,10 @@ audit workpaper package. |
| 13 | 13 | |
| 14 | 14 | ## Installation |
| 15 | 15 | |
| 16 | | Install the repository requirements: |
| 16 | Sampling needs only the `analysis` extra (pandas + Excel support): |
| 17 | 17 | |
| 18 | 18 | ```bash |
| 19 | | pip install -r requirements.txt |
| 19 | pip install ".[analysis]" |
| 20 | 20 | ``` |
| 21 | 21 | |
| 22 | 22 | Supported input formats are `.csv`, `.xlsx`, `.xls`, and `.xlsm`. |
tui/README.md
+1 −1
| @@ -15,7 +15,7 @@ platform-agnostic. |
| 15 | 15 | ## Run it |
| 16 | 16 | |
| 17 | 17 | ```bash |
| 18 | | pip install -r requirements.txt |
| 18 | pip install ".[tui]" # textual + the AWS/GitHub/GitLab collector deps |
| 19 | 19 | python audit_tui.py |
| 20 | 20 | ``` |
| 21 | 21 | |