Skip to main content

CoreTrace Python Analyzer

A standalone static security analyzer for Python. It finds injection vulnerabilities by following attacker-controlled data through the program, across functions, files, objects and closures, and judges each flow against the guards on its path; it reports dangerous API usage, secrets committed in sources and configuration, and vulnerable or forbidden dependencies, correlated with the code that reaches them. It runs offline, on a file or a whole project, with no runtime dependency.

pip install coretrace-python-analyzer
coretrace-python-analyzer --check src/ --format sarif > report.sarif
  • Usage guide: command line, rules, report formats, dependencies and advisories, cache and parallelism, continuous integration.
  • Writing a plugin: models for another framework, detectors for another rule, secret patterns and project-wide checks.
  • Architecture: the engine's design and its migration plan.

The pipeline: source manager, parser-independent high-level representation (PyHIR), semantic resolution of imports and scopes, lowering to a small intermediate representation (PyIR), control-flow graphs, SSA, data-flow and abstract interpretation, interprocedural summaries, taint and refutation, then plugins and reporters.

Development

python -m venv .venv
python -m pip install -e ".[dev]"
python -m mypy
python -m pytest
python -m ruff check .

The non-regression suite analyses the public repositories pinned in tests/regression/repositories.toml and compares findings and coverage with the snapshots in tests/regression/expected/. It clones on first use, needs the network and runs in its own CI job:

python -m pytest -m regression
CORETRACE_REGRESSION_UPDATE=1 python -m pytest -m regression   # record an intended change

License

Apache License 2.0, see LICENSE and NOTICE.

Release files for coretrace-python-analyzer 0.15.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for coretrace-python-analyzer 0.15.0
File Size Uploaded
coretrace_python_analyzer-0.15.0.tar.gz 366.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for coretrace-python-analyzer 0.15.0
File Interpreter ABI Platform
coretrace_python_analyzer-0.15.0-py3-none-any.whl Python 3 none any Details

Total release size: 599.2 kB

Release files / coretrace_python_analyzer-0.15.0.tar.gz

Download URL coretrace_python_analyzer-0.15.0.tar.gz
Size 366.6 kB
Tags Source
SHA-256 checksum
How to use checksums
6e95a92327226a508481f49d76a172f5c9baa483ff9e42872033fd7c37b5f67b
BLAKE2b-256 checksum
How to use checksums
b2225c8d7f5af1b2ae80a5b39f18e6d7db46bbbd29ab3d41e6c2448769c20653
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 26, 2026.

Transparency log

Release files / coretrace_python_analyzer-0.15.0-py3-none-any.whl

Download URL coretrace_python_analyzer-0.15.0-py3-none-any.whl
Size 232.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bdb4f84d110ec1a7fff99342056a71959d50decbe99662d0d3048e1c399af111
BLAKE2b-256 checksum
How to use checksums
b3f8a29d7a59984bbf05b15fbffbe6745c501fd734d987fcf2b5a8adb472ac52
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 26, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.15.0 This release

2 release files

0.14.0

2 release files

0.13.0

2 release files

0.12.0

2 release files

0.11.0

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page