Skip to main content

Customs Inspector

Customs Inspector is a Python tool that hooks into Poetry's package management system to allow for manual auditing of package changes during updates. When you run poetry update, Customs Inspector will open a browser with a GitHub diff like view, requesting you to confirm or reject the update before proceeding.

Demo

YouTube

Note:

TESTED ONLY ON Poetry v1.4.x
This is a proof of concept. Poetry explicitly says to not use the plugin system to modify existing commands. If this is something that is considered valuable, I would love to discuss this with Poetry's authors to potentially integrate it.

Why?

Developers are lazy, we'd rather not audit source code...
Well, we cannot afford that anymore. I am also not interested in the snake oil automated analysis companies are selling (for now).

What if auditing was really easy to do so?
What if, we could harness the community's collective effort to find malicious packages?

Usage

# install the plugin
poetry self add customs-inspector
# run update like you normally would
poetry update

See: how to install plugins

Upcoming:

  • Increase speed
  • Add language server support to make auditing even easier
  • Add file filtering, to hide test folders, for example
  • Add rules for quick auditing, for example when new sensitive APIs are used (socket, os, sys)

Contributions

Feedback, contributions and suggestions welcome.

License

GPL-3.0

Release files for customs-inspector 0.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for customs-inspector 0.2.2
File Size Uploaded
customs_inspector-0.2.2.tar.gz 3.4 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for customs-inspector 0.2.2
File Interpreter ABI Platform
customs_inspector-0.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 6.8 MB

Release files / customs_inspector-0.2.2.tar.gz

Download URL customs_inspector-0.2.2.tar.gz
Size 3.4 MB
Tags Source
SHA-256 checksum
How to use checksums
a20fc7f8077e999fc7b577078b086f6b282c5c7c30303ac082c789c27caca1ae
BLAKE2b-256 checksum
How to use checksums
e1123eea798889301b68421e8e6c41d1a005305b732d63bcf988d522792769b5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.4.1 CPython/3.10.2 Linux/5.10.0-21-amd64

Release files / customs_inspector-0.2.2-py3-none-any.whl

Download URL customs_inspector-0.2.2-py3-none-any.whl
Size 3.4 MB
Tags Python 3
SHA-256 checksum
How to use checksums
dee0cbb188651b3fbf50b4548e1b95c2bd46ef4aad7fc791eb55e9776167f71b
BLAKE2b-256 checksum
How to use checksums
e9b74d5ae7cd00b2f412689cc6a1697db1bf96b450f872f22f67292680586e06
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.4.1 CPython/3.10.2 Linux/5.10.0-21-amd64

Release history Release notifications | RSS feed

This release

0.2.2 This release

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page