# \[ANN\] opam-audit

**URL:** <https://discuss.ocaml.org/t/ann-opam-audit/18438>\
**Category:** Ecosystem\
**Tags:** security, announce\
**Created:** [August 10, 2026, 8:46pm UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438 "2026-08-10T20:46:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hannes](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/hannes/32/2302_2.png) [@hannes](https://discuss.ocaml.org/u/hannes)\
**Post date:** [August 10, 2026, 8:46pm UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/1 "2026-08-10T20:46:08Z")

</div>

Dear everyone,

I’m happy to announce that `opam-audit` has been released to opam in its initial version. It is an opam plugin (so you install it in one switch and have it available in all switches as `opam audit`).

So, opam-audit keeps a local copy of the security-advisory database from the [OCaml Security Team](https://ocaml.org/security). When you run `opam audit`, it will inspect all installed packages in your switch against the known advisories and report which installed packages have a known security vulnerability.

It either returns 0 if no known vulnerable packages were found, or non-zero and a list of installed vulnerable packages. This way, your CI systems can before publishing your application call `opam audit` and ensure that no vulnerable package sneaked into your binary.

An earlier mention in here [Request for comments: What to do with opam packages that have known security vulnerabilities - #2 by dbuenzli](https://discuss.ocaml.org/t/request-for-comments-what-to-do-with-opam-packages-that-have-known-security-vulnerabilities/18087/2)

Source code at [GitHub - hannesm/opam-audit: Audit your opam switch for vulnerable packages · GitHub](https://github.com/hannesm/opam-audit) - bug reports and feature requests are very welcome.

---

<div class="post-metadata">

**Author:** ![aguluman](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/aguluman/32/5709_2.png) [@aguluman](https://discuss.ocaml.org/u/aguluman)\
**Post date:** [August 10, 2026, 10:05pm UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/2 "2026-08-10T22:05:17Z")

</div>

Thank you for this information.

Much appreciated.

---

<div class="post-metadata">

**Author:** ![aguluman](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/aguluman/32/5709_2.png) [@aguluman](https://discuss.ocaml.org/u/aguluman)\
**Post date:** [August 13, 2026, 8:40am UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/3 "2026-08-13T08:40:43Z")

</div>

Hello Hannes.

I have installed opam audit and I ran it, I have 4 vulnerable packages in my switch.

The vulnerable packages can not be upgraded because, `∗ mirage-crypto-rng-lwt.1.2.0 is installed and requires mirage-crypto-rng = 1.2.0`

I saw you have resolved the vulnerabilities in `mirage-crypto 2.3.0` from [opam.ocaml.org](http://opam.ocaml.org)

I want to know if you have taken a look at `mirage-crypto-rng-lwt.1.2.0` to bring it up to version 2.3.0

I can help out if you would be willing.

Cheers.

---

<div class="post-metadata">

**Author:** ![reynir](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/reynir/32/6496_2.png) [@reynir](https://discuss.ocaml.org/u/reynir)\
**Post date:** [August 13, 2026, 9:06am UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/4 "2026-08-13T09:06:12Z")

</div>

@aguluman `mirage-crypto-rng-lwt` was removed in 2.0.0. See [remove now superfluous mirage-crypto-rng-{lwt,eio,async} by hannesm · Pull Request #256 · mirage/mirage-crypto · GitHub](https://github.com/mirage/mirage-crypto/pull/256)

So I think the way forward for you is to look if you can remove `mirage-crypto-rng-lwt` and if not see if you can update the dependents to not depend on `mirage-crypto-rng-lwt`.

---

<div class="post-metadata">

**Author:** ![aguluman](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/aguluman/32/5709_2.png) [@aguluman](https://discuss.ocaml.org/u/aguluman)\
**Post date:** [August 13, 2026, 9:53am UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/5 "2026-08-13T09:53:46Z")

</div>

Hello @reynir  
Thank you for this information.  
This is helpful.

Cheers

---

<div class="post-metadata">

**Author:** ![hannes](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/hannes/32/2302_2.png) [@hannes](https://discuss.ocaml.org/u/hannes)\
**Post date:** [August 15, 2026, 6:06am UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/6 "2026-08-15T06:06:02Z")

</div>

And, did it work? Or did you have any packages that are still depending on mirage-crypto-rng-lwt? (if so, let me know, I can spend time to get rid of this dependency.)

---

<div class="post-metadata">

**Author:** ![aguluman](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/aguluman/32/5709_2.png) [@aguluman](https://discuss.ocaml.org/u/aguluman)\
**Post date:** [August 15, 2026, 8:25am UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/7 "2026-08-15T08:25:37Z")

</div>

It did work.

I pinned dream master branch using opam.  
That resolved \*-lwt issue. I uninstalled it and upgraded mirage crypto.

@reynir comment was helpful.

---

<div class="post-metadata">

**Author:** ![dbuenzli](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/dbuenzli/32/18_2.png) [@dbuenzli](https://discuss.ocaml.org/u/dbuenzli)\
**Post date:** [August 15, 2026, 3:16pm UTC](https://discuss.ocaml.org/t/ann-opam-audit/18438/8 "2026-08-15T15:16:18Z")

</div>

A post was split to a new topic: [Email and smtp for Mirage](https://discuss.ocaml.org/t/email-and-smtp-for-mirage/18455)
