Skip to main content

Python File Audit

PythonCodeAudit Badge OpenSSF Best Practices PyPI - Version Documentation License

File Audit – Simplify Python Secure Programming by adding one line! Build secure Python applications by default. Validate files before you use them.

Python File Audit protects you from using insecure files and file-based attacks with a comprehensive set of safety checks.

Safety Checks

  • File size limit – Prevents oversized files from being processed
  • GZip decompression ratio – Guards against decompression bombs
  • Tar member count – Limits the number of entries inside tar archives
  • Total extracted size – Caps the overall size of extracted content
  • Individual file size – Enforces a maximum size per extracted file
  • Path traversal protection – Blocks ../ and absolute path tricks
  • Reject symlinks – Disallows symbolic links
  • Reject hardlinks – Disallows hard links
  • Reject device files – Blocks device nodes
  • Reject FIFOs – Blocks named pipes
  • Filename length – Enforces a maximum filename length
  • Directory depth – Limits how deeply nested directories can be

These checks can be used via a simple API or by adding a decorator — without changing your existing code.

Installation

pip install fileaudit

Installation

pip install fileaudit

Usage

API / Decorator (CSV example)

Validate a local CSV file:

validate_csv("data.csv")

Validate a CSV file from a URL:

validate_csv("https://example.com/data.csv")

Use as a decorator (first function argument is treated as the CSV path):

@validate_csv
def process_csv(csv_path):
    ...

Use as a decorator with default validation options:

@validate_csv()
def process_csv(csv_path):
    ...

Specify the decorated function argument that contains the CSV path:

@validate_csv("input_file")
def process_csv(input_file):
    ...

Configure validation limits:

@validate_csv(
    max_file_size=10 * 1024 * 1024,
    max_rows=10_000,
    max_columns=50,
)
def process_csv(csv_path):
    ...

CLI

You can also inspect a file directly from the command line:

fileaudit path/to/file

Supported File Types

File types are auto-detected from the extension:

Extension Description
csv CSV files
gz GZIP files
json JSON files
py Python source files
tar TAR archives
tar-gz TAR.GZ archives
tgz TAR.GZ archives
xml XML files
zip ZIP archives

Python File Audit helps you validate files before they reach your application logic, reducing the risk of common file-based attacks.

Contributing

All contributions are welcome! Think of corrections on the documentation, code or more and better tests.

Simple Guidelines:

  • Questions, Feature Requests, Bug Reports please use on the Github Issue Tracker.

Pull Requests are welcome!

When you contribute to FileAudit, your contributions are made under the same license as the file you are working on.

[!NOTE] This is an open community driven project. Contributors will be mentioned in the documentation.

We adopt the Collective Code Construction Contract(C4) to streamline collaboration.

License

fileaudit is distributed under the terms of the Mozilla Public License 2.0 license.

Metadata

Release files for fileaudit 0.2.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for fileaudit 0.2.3
File Size Uploaded
fileaudit-0.2.3.tar.gz 10.1 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for fileaudit 0.2.3
File Interpreter ABI Platform
fileaudit-0.2.3-py3-none-any.whl Python 3 none any Details

Total release size: 10.2 MB

Release files / fileaudit-0.2.3.tar.gz

Download URL fileaudit-0.2.3.tar.gz
Size 10.1 MB
Tags Source
SHA-256 checksum
How to use checksums
0cddcb86318f3d7d7238584a072bbc66e1d74076f33415c4db1b1bb86d37cb26
BLAKE2b-256 checksum
How to use checksums
0ee2e04364e24db98692813ecaede4b74e8dda8ad01511e7a1c3b612056d1ffc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via Hatch/1.18.0 {"ci":null,"cpu":"x86_64","distro":{"id":"noble","libc":{"lib":"glibc","version":"2.39"},"name":"Ubuntu","version":"24.04"},"implementation":{"name":"CPython","version":"3.14.6"},"installer":{"name":"hatch","version":"1.18.0"},"openssl_version":"OpenSSL 3.6.3 9 Jun 2026","python":"3.14.6","system":{"name":"Linux","release":"6.8.0-138-generic"}} HTTPX2/2.10.0

Release files / fileaudit-0.2.3-py3-none-any.whl

Download URL fileaudit-0.2.3-py3-none-any.whl
Size 54.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bf79ec8843025d08b1feac30f7f8a3953d9d89bfa943b1afd82f41d205037305
BLAKE2b-256 checksum
How to use checksums
ab8c84fffb9cf3dab6decfd39b15092a52a30293afb50dd3845924487014582c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via Hatch/1.18.0 {"ci":null,"cpu":"x86_64","distro":{"id":"noble","libc":{"lib":"glibc","version":"2.39"},"name":"Ubuntu","version":"24.04"},"implementation":{"name":"CPython","version":"3.14.6"},"installer":{"name":"hatch","version":"1.18.0"},"openssl_version":"OpenSSL 3.6.3 9 Jun 2026","python":"3.14.6","system":{"name":"Linux","release":"6.8.0-138-generic"}} HTTPX2/2.10.0

Release history Release notifications | RSS feed

This release

0.2.3 This release

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page