Skip to main content

A software supply chain risk management tool

Project description

Boomgate

Identify and mitigate the risks of using third-party libraries.

PyPI version Release workflow status


This project is not remotely ready for anyone to look at, let alone use. It is in a very early proof-of-concept stage, focusing on iterative research and development. I have not settled on the project's architecture, and I am still exploring the problem space. As such, the quality of the code is very poor, and things are guaranteed to change.

I will not provide support, nor will I accept PRs at this time.


Vision

I intend for Boomgate to allow you to define a policy for your project that describes the risks you are willing to accept when using third-party libraries. Boomgate will evaluate your project's dependencies against this policy, report on any risks that you deem unacceptable, and—also per your defined policy—suggest mitigation strategies.

For example, you may decide that you are not willing to use a dependency if its author's email address's domain is not registered (i.e. DNS returns NXDOMAIN), or you may decide that all dependencies (barring a list of excepted 'trusted' dependencies) require a security audit before they can be used.

In this example, Boomgate can be configured to block your project's CI/CD pipeline if one of these conditions is met by your project's resolved dependencies.

See my rough list of idea in the GitHub issues list.

Developing

Clone the repository and run the following command:

uv pip install -e . -r pyproject.toml --extra=dev --extra=docs

This will install the project in editable mode with all development dependencies.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

boomgate-0.0.1a1.tar.gz (32.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

boomgate-0.0.1a1-py3-none-any.whl (32.9 kB view details)

Uploaded Python 3

File details

Details for the file boomgate-0.0.1a1.tar.gz.

File metadata

  • Download URL: boomgate-0.0.1a1.tar.gz
  • Upload date:
  • Size: 32.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.0.0 CPython/3.12.2

File hashes

Hashes for boomgate-0.0.1a1.tar.gz
Algorithm Hash digest
SHA256 e09e82f5e6ce3f7bfb11fc477d26c4cee922d7b56cbeeacc0e081221b669b41c
MD5 263df6bfa4005087d92057003cc44fbe
BLAKE2b-256 18fa5a24dedf33a51c0fa042ef177fdeab1df7c0c94c6cab35a2436928bcba7c

See more details on using hashes here.

File details

Details for the file boomgate-0.0.1a1-py3-none-any.whl.

File metadata

  • Download URL: boomgate-0.0.1a1-py3-none-any.whl
  • Upload date:
  • Size: 32.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.0.0 CPython/3.12.2

File hashes

Hashes for boomgate-0.0.1a1-py3-none-any.whl
Algorithm Hash digest
SHA256 c8da21575a339c5f928c4e72e164e9ff5649ce46652b08978b0838fd135a4502
MD5 784aac73859b82119ffeb7da0b9fa5c5
BLAKE2b-256 a06790d68bcca6a3799a6101c3eb39ba77ebce41a6f060dcaa0d7419eceaae1f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page