What pip-audit Misses: EPSS-Aware Vulnerability Prioritization for Python
pip-audit finds vulnerabilities in your Python dependencies but ranks them by CVSS severity, not exploit probability. Three concrete gaps cause missed priorities, false urgency, and blind spots during the NVD-to-PyPI advisory lag window.