Given the recent changes with our way of checking the packages, I think we could update the check-vulnerability action to avoid installing packages. Previously we didn't leverage a requirement file with safety but given that's our way of working now... I think we could simply do something like
uv export --frozen --format requirements-txt -o requirements-for-safety.txt --extra EXTRA_TARGET --no-hashes
and the same is probably available in poetry.
This might require some thoughts to align with the skip-install input logic.
Given the recent changes with our way of checking the packages, I think we could update the check-vulnerability action to avoid installing packages. Previously we didn't leverage a requirement file with safety but given that's our way of working now... I think we could simply do something like
uv export --frozen --format requirements-txt -o requirements-for-safety.txt --extra EXTRA_TARGET --no-hashesand the same is probably available in poetry.
This might require some thoughts to align with the
skip-installinput logic.