Skip to main content

Override Poetry's update command to audit packages before they are updated

Project description

Customs Inspector

Customs Inspector is a Python tool that hooks into Poetry's package management system to allow for manual auditing of package changes during updates. When you run poetry update, Customs Inspector will open a browser with a GitHub diff like view, requesting you to confirm or reject the update before proceeding.

Note:

TESTED ONLY ON Poetry v1.4.x
This is a proof of concept. Poetry explicitly says to not use the plugin system to modify existing commands. If this is something that is considered valuable, I would love to discuss this with Poetry's authors to potentially integrate it.

Why?

Developers are lazy, we'd rather not audit source code...
Well, we cannot afford that anymore. I am also not interested in the snake oil automated analysis companies are selling (for now).

What if auditing was really easy to do so?
What if, we could harness the community's collective effort to find malicious packages?

Usage

See: how to install plugins
To update:

pip install customs-inspector
poetry update

Upcoming:

  • Increase speed
  • Add language server support to make auditing even easier
  • Add file filtering, to hide test folders, for example
  • Add rules for quick auditing, for example when new sensitive APIs are used (socket, os, sys)

Contributions

Feedback, contributions and suggestions welcome.

License

GPL-3.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

customs_inspector-0.1.1.tar.gz (3.4 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

customs_inspector-0.1.1-py3-none-any.whl (3.4 MB view details)

Uploaded Python 3

File details

Details for the file customs_inspector-0.1.1.tar.gz.

File metadata

  • Download URL: customs_inspector-0.1.1.tar.gz
  • Upload date:
  • Size: 3.4 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.4.1 CPython/3.10.2 Linux/5.10.0-21-amd64

File hashes

Hashes for customs_inspector-0.1.1.tar.gz
Algorithm Hash digest
SHA256 d87aebbd5a6acbd98141b0c6152dd9b4379753d0b967bb722644047c2babf42c
MD5 a186a2244ef29b85432d34719327f7a3
BLAKE2b-256 a3800eb21b83124af03b9b5fce3da5988144eeea9df1aed189b72dd82a9d9da8

See more details on using hashes here.

File details

Details for the file customs_inspector-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: customs_inspector-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 3.4 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.4.1 CPython/3.10.2 Linux/5.10.0-21-amd64

File hashes

Hashes for customs_inspector-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 13d443b32be57470303240d2e77d7cf4bc6e5dd2f71da92b72c4fb102c866704
MD5 a01e5b62bd9f3de8a2d7085111af2cd8
BLAKE2b-256 ec747f6ef84f3d382d10641f4cec1c8f49a61e17803b63cc49b944b6097e6b87

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page