Known vulnerabilities are tracked in OSV and the Python Packaging Advisory Database. For CI, use pip-audit. To look at a package before you install it, open it on PyDeps. You get findings for that version and the leaves under it, plus fix versions, KEV, and EPSS when the source has them.
pip-audit and pip-audit -r requirements.txt gate lockfiles in pipelines.
Open a package page to review advisories on the header, expand the tree for transitive risk, then optionally download an offline bundle only after you accept the posture.