Skip to main content

Flavor Pack packaging system implementing Progressive Secure Package Format (PSPF/2025)

Project description

FlavorPack: Progressive Secure Polyglot Packaging Toolchain

License Python 3.11+ uv Ruff CI

⚠️ Alpha Software: FlavorPack is in early development. APIs, file formats, and commands may change without notice. Not recommended for production use. Check current version with flavor --version. Install from source only.

FlavorPack is a cross-language packaging system that creates self-contained, portable executables using the Progressive Secure Package Format (PSPF) 2025 Edition. It enables you to ship Python applications as single binaries that "just work" - no installation, no dependencies, no configuration required.

Note: The package name is flavorpack, but the command-line tool is flavor.

🎯 Key Features

  • Single-File Distribution: Package entire applications into one executable file
  • Cross-Language Support: Python orchestrator with Go and Rust launchers
  • Secure by Default: Ed25519 signature verification ensures package integrity
  • Progressive Extraction: Extract only what's needed, when it's needed
  • Smart Caching: Persistent work environment with intelligent validation
  • Zero Dependencies: End users need nothing pre-installed

🚀 Quick Start

Prerequisites

  • Python 3.11 or higher
  • UV package manager (curl -LsSf https://astral.sh/uv/install.sh | sh)
  • Go 1.26+ and Rust 1.86+ (for building helpers - see src/flavor-go/go.mod and src/flavor-rs/Cargo.toml)

Installation (Source Only)

Note: FlavorPack is not yet available on PyPI. Source installation is currently the only option.

# Clone the repository
git clone https://github.com/provide-io/flavorpack.git
cd flavorpack

# Set up environment and install dependencies
uv sync

# Build the Go and Rust helpers (required)
make build-helpers
# or directly: ./build.sh

Creating Your First Package

# Package a Python application
flavor pack --manifest pyproject.toml --output myapp.psp

# Run the packaged application
./myapp.psp

# Verify package integrity
flavor verify myapp.psp

📦 PSPF Format

The Progressive Secure Package Format is a polyglot file format that works as both an OS executable and a structured package. Each .psp file contains a native launcher, package metadata, and compressed data slots.

See the PSPF Format Specification for the complete binary layout diagram and technical details.

📚 Documentation

🏗️ Architecture

FlavorPack consists of three main components:

  1. Python Orchestrator (src/flavor/)

    • Manages the build process and dependency resolution
    • Creates manifests and handles Python packaging
    • Provides CLI interface for package operations
  2. Native Helpers (src/flavor-go/, src/flavor-rs/)

    • Launchers: Extract and execute packages at runtime, perform Ed25519 signature verification, manage workenv caching
    • Builders: Assemble PSPF packages from manifests, implement the PSPF/2025 binary format, handle slot packing and metadata encoding
    • Built binaries are placed in dist/bin/ for distribution

🔒 Security

Every PSPF package includes cryptographic integrity verification:

  • Ed25519 signatures ensure packages haven't been tampered with
  • Public keys are embedded in the package index
  • Signature verification happens automatically on every launch
  • Optional deterministic builds with --key-seed for reproducibility

🧪 Testing

# Run the test suite
make test

# Run with coverage
make test-cov

# Test cross-language compatibility
make validate-pspf

# Run specific test categories
pytest -m unit        # Fast unit tests
pytest -m integration # Integration tests
pytest -m security    # Security tests

# Test cross-language compatibility with Pretaster
make validate-pspf

Test Taxonomy

FlavorPack uses a shared test-intent taxonomy across Python, Go, and Rust. Use the root make targets instead of guessing which language-native runner to invoke first.

make test-unit
make test-integration
make test-cross-language
make test-security
make test-adversarial
make test-property
make test-fuzz
make test-mutation
make test-smoke
make test-fast
make test-slow

Intent categories:

  • unit: small isolated behaviors
  • integration: multi-component behavior in one implementation
  • cross_language: parity/interoperability across Python, Go, and Rust
  • security: trust, verification, integrity, permissions, policy
  • adversarial: hostile inputs and boundary-violation attempts
  • property: parameterized and invariant-driven tests
  • fuzz: native malformed-input discovery
  • mutation: test-suite strength checks
  • smoke: minimal high-signal sanity checks

Cost selectors are separate from intent:

  • fast
  • slow
  • ci

Use both security and adversarial when a test intentionally tries to violate a security boundary.

Quality Engineering

Use the root quality targets to run the same cross-language workflows locally that CI now runs as observational jobs:

make quality-python-fast
make quality-python-deep
make quality-go-fast
make quality-go-deep
make quality-rust-fast
make quality-rust-deep
make quality-ci

The tools run in strict mode. In this rollout phase, the dedicated quality-observability jobs are wired into CI but are not intended to be required merge checks yet. A failing observability job means that the quality workflow itself surfaced an issue; merge policy remains a separate repository setting.

🙏 Acknowledgments

FlavorPack is built on the shoulders of giants:

  • UV for fast Python package management
  • The Python, Go, and Rust communities for excellent tooling

Built with ❤️ by the provide.io team

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

flavorpack-0.3.21-py3-none-win_arm64.whl (8.7 MB view details)

Uploaded Python 3Windows ARM64

flavorpack-0.3.21-py3-none-win_amd64.whl (9.5 MB view details)

Uploaded Python 3Windows x86-64

flavorpack-0.3.21-py3-none-manylinux2014_x86_64.whl (9.1 MB view details)

Uploaded Python 3

flavorpack-0.3.21-py3-none-macosx_11_0_arm64.whl (8.3 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

flavorpack-0.3.21-py3-none-macosx_10_9_x86_64.whl (8.9 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file flavorpack-0.3.21-py3-none-win_arm64.whl.

File metadata

  • Download URL: flavorpack-0.3.21-py3-none-win_arm64.whl
  • Upload date:
  • Size: 8.7 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for flavorpack-0.3.21-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 c8cb346a4affaecc889d22063aa3b74de09fa71701621ead22307a83a9e35c08
MD5 79de0fcd7cee46633ee4add384ec66fd
BLAKE2b-256 7b78daa09f37a995b6f8696ee259b0a7d88b2d780994d147922c38a96eb90f3c

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.3.21-py3-none-win_arm64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.3.21-py3-none-win_amd64.whl.

File metadata

  • Download URL: flavorpack-0.3.21-py3-none-win_amd64.whl
  • Upload date:
  • Size: 9.5 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for flavorpack-0.3.21-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 09eedb04946e005897dd40d3d5b2f2f2fb6d4599b7483365a169d9291b836c84
MD5 90b715d31ccda9be31b44a2fe1ab62f3
BLAKE2b-256 597e1250b664593dfae21371a4285516880128cd75021024c8124987fc861206

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.3.21-py3-none-win_amd64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.3.21-py3-none-manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for flavorpack-0.3.21-py3-none-manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 f0fea1582af0af01d4f9c2e448feec0b09e6b27fe631e1d61180536e697a8cae
MD5 e6e0ebeefa004b876c0f042fd92ec48d
BLAKE2b-256 8eddd4f08fbf5e0bca87eb06c68f0652c47db55dc51df7ac434b29dbd3ff6765

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.3.21-py3-none-manylinux2014_x86_64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.3.21-py3-none-manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for flavorpack-0.3.21-py3-none-manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 1e6d82bb9121ede99a69461754d706842b875e3bea40c83cf7ce188a5077ca44
MD5 9f8e6f6830e764c5d91c65d160502843
BLAKE2b-256 7dead0b08addf75800ebbbcb457d8934dc88147e6da4947e8ca48c04a51d9732

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.3.21-py3-none-manylinux2014_aarch64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.3.21-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for flavorpack-0.3.21-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 e73f0d72eab35cac8496297ab8baf850d2f00baaeba50a71732221a2d642966b
MD5 ec15820cf01e6ec3681cd620e2a30114
BLAKE2b-256 25db2cdb031519aa72ff602d910650c38b85f54495effb0da629e64e705bd0af

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.3.21-py3-none-macosx_11_0_arm64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.3.21-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for flavorpack-0.3.21-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 9b7db5721a611c29f5930cdda752723646e82aea26e7aedb2c6cb6808f0b76f3
MD5 93388709929143f85b564bb3057247e0
BLAKE2b-256 01b5228938311b3ad2f2b2ce20c3a4fbaac8c1d85d74a9179c1068320541615b

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.3.21-py3-none-macosx_10_9_x86_64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page