Skip to main content

Flavor Pack packaging system implementing Progressive Secure Package Format (PSPF/2025)

Project description

Flavorpack: Progressive Secure Polyglot Packaging Toolchain

License Python 3.11+ uv Ruff CI

Beta: Flavorpack is under active development. The PSPF 2025 format is stable, and core packaging workflows are tested across 6 platforms (Linux, macOS, Windows, FreeBSD — amd64/arm64). APIs may still evolve before 1.0.

Flavorpack is a cross-language packaging system that creates self-contained, portable executables using the Progressive Secure Package Format (PSPF) 2025 Edition. It enables you to ship Python applications as single binaries that "just work" - no installation, no dependencies, no configuration required.

Note: The package name is flavorpack, but the command-line tool is flavor.

🎯 Key Features

  • Single-File Distribution: Package entire applications into one executable file
  • Cross-Language Support: Python orchestrator with Go and Rust launchers
  • Secure by Default: Ed25519 signature verification ensures package integrity
  • Progressive Extraction: Extract only what's needed, when it's needed
  • Smart Caching: Persistent work environment with intelligent validation
  • Zero Dependencies: End users need nothing pre-installed

🚀 Quick Start

Prerequisites

  • Python 3.11 or higher
  • UV package manager (curl -LsSf https://astral.sh/uv/install.sh | sh)
  • Go 1.26+ and Rust 1.86+ (for building helpers - see src/flavor-go/go.mod and src/flavor-rs/Cargo.toml)

Installation (Source Only)

Note: Flavorpack is not yet available on PyPI. Source installation is currently the only option.

# Clone the repository
git clone https://github.com/provide-io/flavorpack.git
cd flavorpack

# Set up environment and install dependencies
uv sync

# Build the Go and Rust helpers (required)
make build-helpers
# or directly: ./build.sh

Creating Your First Package

# Package a Python application
flavor pack --manifest pyproject.toml --output myapp.psp

# Run the packaged application
./myapp.psp

# Verify package integrity
flavor verify myapp.psp

📦 PSPF Format

The Progressive Secure Package Format is a polyglot file format that works as both an OS executable and a structured package. Each .psp file contains a native launcher, package metadata, and compressed data slots.

See the PSPF Format Specification for the complete binary layout diagram and technical details.

📚 Documentation

🏗️ Architecture

Flavorpack consists of three main components:

  1. Python Orchestrator (src/flavor/)

    • Manages the build process and dependency resolution
    • Creates manifests and handles Python packaging
    • Provides CLI interface for package operations
  2. Native Helpers (src/flavor-go/, src/flavor-rs/)

    • Launchers: Extract and execute packages at runtime, perform Ed25519 signature verification, manage workenv caching
    • Builders: Assemble PSPF packages from manifests, implement the PSPF/2025 binary format, handle slot packing and metadata encoding
    • Built binaries are placed in dist/bin/ for distribution

🔒 Security

Every PSPF package includes cryptographic integrity verification:

  • Ed25519 signatures ensure packages haven't been tampered with
  • Public keys are embedded in the package index
  • Signature verification happens automatically on every launch
  • Optional deterministic builds with --key-seed for reproducibility

🧪 Testing

# Run the test suite
make test

# Run with coverage
make test-cov

# Test cross-language compatibility
make validate-pspf

# Run specific test categories
pytest -m unit        # Fast unit tests
pytest -m integration # Integration tests
pytest -m security    # Security tests

# Test cross-language compatibility with Pretaster
make validate-pspf

Test Taxonomy

Flavorpack uses a shared test-intent taxonomy across Python, Go, and Rust. Use the root make targets instead of guessing which language-native runner to invoke first.

make test-unit
make test-integration
make test-cross-language
make test-security
make test-adversarial
make test-property
make test-fuzz
make test-mutation
make test-smoke
make test-fast
make test-slow

Intent categories:

  • unit: small isolated behaviors
  • integration: multi-component behavior in one implementation
  • cross_language: parity/interoperability across Python, Go, and Rust
  • security: trust, verification, integrity, permissions, policy
  • adversarial: hostile inputs and boundary-violation attempts
  • property: parameterized and invariant-driven tests
  • fuzz: native malformed-input discovery
  • mutation: test-suite strength checks
  • smoke: minimal high-signal sanity checks

Cost selectors are separate from intent:

  • fast
  • slow
  • ci

Use both security and adversarial when a test intentionally tries to violate a security boundary.

Quality Engineering

Use the root quality targets to run the same cross-language workflows locally that CI now runs as observational jobs:

make quality-python-fast
make quality-python-deep
make quality-go-fast
make quality-go-deep
make quality-rust-fast
make quality-rust-deep
make quality-ci

The tools run in strict mode. In this rollout phase, the dedicated quality-observability jobs are wired into CI but are not intended to be required merge checks yet. A failing observability job means that the quality workflow itself surfaced an issue; merge policy remains a separate repository setting.

🙏 Acknowledgments

Flavorpack is built on the shoulders of giants:

  • UV for fast Python package management
  • The Python, Go, and Rust communities for excellent tooling

Built with ❤️ by the provide.io team

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

flavorpack-0.4.2-py3-none-win_arm64.whl (8.6 MB view details)

Uploaded Python 3Windows ARM64

flavorpack-0.4.2-py3-none-win_amd64.whl (9.4 MB view details)

Uploaded Python 3Windows x86-64

flavorpack-0.4.2-py3-none-manylinux2014_x86_64.whl (8.9 MB view details)

Uploaded Python 3

flavorpack-0.4.2-py3-none-manylinux2014_aarch64.whl (8.1 MB view details)

Uploaded Python 3

flavorpack-0.4.2-py3-none-macosx_11_0_arm64.whl (8.2 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

flavorpack-0.4.2-py3-none-macosx_10_9_x86_64.whl (8.9 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file flavorpack-0.4.2-py3-none-win_arm64.whl.

File metadata

  • Download URL: flavorpack-0.4.2-py3-none-win_arm64.whl
  • Upload date:
  • Size: 8.6 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for flavorpack-0.4.2-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 696f07ef0cb5ef83148e45dad4db123f65e9cc1d1380f4e1803761ae407d70ee
MD5 3509333d8e46878197f6769d58c30ad5
BLAKE2b-256 6d2fcf838facc06af7d3f4d8619d6ec3024cbfa7f02bd81df83951f948f88db9

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.4.2-py3-none-win_arm64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.4.2-py3-none-win_amd64.whl.

File metadata

  • Download URL: flavorpack-0.4.2-py3-none-win_amd64.whl
  • Upload date:
  • Size: 9.4 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for flavorpack-0.4.2-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 80823d6319834fd34a306369e41ffb265ea5e13991dfc28ffaa06d72346b8e7c
MD5 1b68d86a1391c36f30a72b9f460ccf0b
BLAKE2b-256 afb4f4503be022a9eb088bf045ac9dbd5f17dffd9c18eaaa7ecae355af68c918

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.4.2-py3-none-win_amd64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.4.2-py3-none-manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for flavorpack-0.4.2-py3-none-manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 1407c18754626a1e882b7e7e5f1af997c93f742200b243c56975bfc1922dda93
MD5 98b37c335c3c764c8ab060f7089453f9
BLAKE2b-256 eb8f1f967fd525e356ee0a64aecef1e4e9cd3abbfaac3c9c3f29db79e6bc0730

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.4.2-py3-none-manylinux2014_x86_64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.4.2-py3-none-manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for flavorpack-0.4.2-py3-none-manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 0e676c3e6b2ac9c2d2a353caf3c98211e1666f0197f301d9fed96eb08dae594a
MD5 cb583bc3e35c25188d9a36676057f61d
BLAKE2b-256 0fa2f3e866545542a91d4bd5ae36cec25761807b32c771e0843b53c2c9b475dc

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.4.2-py3-none-manylinux2014_aarch64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.4.2-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for flavorpack-0.4.2-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 6d13c417a686ee3afc3aebb283690f3317f8d5e3941963a2649729482862fea8
MD5 2e25b8eeb8a5911346ac1e2811299002
BLAKE2b-256 3e35bf83d584024ee18df4ad91a9c378f37257178a225b99540f3253f327af8f

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.4.2-py3-none-macosx_11_0_arm64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file flavorpack-0.4.2-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for flavorpack-0.4.2-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 05ad1302093081a1df4547e06e4a12d12ba36be39e301094ad632bfa7cd02d43
MD5 2e471d4f94390cdd3c4d9b61bd6143aa
BLAKE2b-256 72b4c448606714f1dd92b1fbdf4eab3b723240bb64d58dd03531409dd03e5b53

See more details on using hashes here.

Provenance

The following attestation bundles were made for flavorpack-0.4.2-py3-none-macosx_10_9_x86_64.whl:

Publisher: release.yml on provide-io/flavorpack

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page