Skip to main content

knime-passbolt-py

PyPI version Python versions License: Apache-2.0 CI

Python wrapper for consuming Passbolt credentials in KNIME Python Script nodes, via the Credential to Python bridge node shipped in the knime-passbolt extension.

Install

The package is distributed via PyPI. A conda-forge feedstock is planned but not yet available — mamba install knime-passbolt-py / conda install knime-passbolt-py will fail until then.

pip install knime-passbolt-py

Inside a conda or mamba environment, install with pip after ensuring pip itself is present:

mamba install python=3.10 pip
pip install knime-passbolt-py

The package is pure-Python with no compiled dependencies, so a pip install inside a conda env is safe.

Usage

In a KNIME workflow, wire:

Passbolt Connector → Get Secret → Credential to Python → Python Script

In the Python Script node:

import knime.scripting.io as knio
import requests

cred = knio.input_objects[0]  # PassboltSecret instance

with cred as c:  # bytearray zeroed on __exit__
    h = c.basic_auth_header()
    resp = requests.get(url, headers={"Authorization": h.decode()})

Security model

The credential lives in the KNIME JVM, in the existing in-memory CredentialCache owned by the upstream Get Secret node. This wrapper carries only a loopback broker URL (http://127.0.0.1:<port>/v1/auth-header) and a short-lived bearer token. The Authorization header is fetched on demand, held in a bytearray, and zeroed (ctypes.memset) when the with block exits.

  • __slots__ prevents __dict__ introspection.
  • __repr__ shows the (non-secret) broker URL and a truncated session UUID; the token and credential bytes are never included.
  • __reduce__ re-pickles to the broker handshake — credential bytes are never serialized, even by accident.
  • Broker URL is validated to be loopback at every fetch; tampering with a saved pickle to redirect to an external host is rejected client-side.

Limits. In-process Python code can read the bytearray while the with block is open. CPython does not provide hardware-enforced isolation. The posture is on par with KNIME's own Credentials Configuration flow variable combined with a disciplined helper class — better is not achievable in CPython without sandboxing.

Supply-chain provenance

Releases are published to PyPI from GitHub Actions using OIDC Trusted Publishing — no long-lived API token is stored anywhere. Each release also ships PEP 740 attestations linking the artifacts to the exact workflow run that built them. To report a vulnerability, see SECURITY.md.

Compatibility

This package version (0.1.2) is compatible with the knime-passbolt KNIME extension version 0.1.1.20260520 and later. The full extension-↔-package compatibility matrix lives in CONTRACT.md.

Changelog

See CHANGELOG.md for per-release notes, including the security hardening recorded for each version.

License

Apache 2.0. See the LICENSE file shipped with this package, or https://www.apache.org/licenses/LICENSE-2.0.

About

knime-passbolt-py is published by Datanautics GmbH as the companion Python package for the knime-passbolt KNIME extension.

Source: https://github.com/DataNautics-GmbH/knime-passbolt-py Issues: https://github.com/DataNautics-GmbH/knime-passbolt-py/issues

Metadata

Release files for knime-passbolt-py 0.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for knime-passbolt-py 0.1.3
File Size Uploaded
knime_passbolt_py-0.1.3.tar.gz 19.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for knime-passbolt-py 0.1.3
File Interpreter ABI Platform
knime_passbolt_py-0.1.3-py3-none-any.whl Python 3 none any Details

Total release size: 35.1 kB

Release files / knime_passbolt_py-0.1.3.tar.gz

Download URL knime_passbolt_py-0.1.3.tar.gz
Size 19.6 kB
Tags Source
SHA-256 checksum
How to use checksums
9eb2a4a8efe2ed3112afe680174b268d030964d8246d459c2957c090ffd51566
BLAKE2b-256 checksum
How to use checksums
417e5322f66a5360b842b0e87c695f1e3a5a231beff6b2eafb4f704b13e32606
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.

Transparency log

Release files / knime_passbolt_py-0.1.3-py3-none-any.whl

Download URL knime_passbolt_py-0.1.3-py3-none-any.whl
Size 15.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2685eea766be528e1ab4bec0464a9a5f1126767467abdec0cdad51bcfffcaf16
BLAKE2b-256 checksum
How to use checksums
54ec6dad01239e0acf64785daafa71661daa8d87738d5b21dfa8af8dfb3aaeb0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.3 This release

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page