PackSafe
An intelligent security gatekeeper for the open-source supply chain. PackSafe evaluates packages before installation and gives you a safety score, an explanation, and an install gate.
Install
uv tool install packsafe
# or
pipx install packsafe
# or, for a one-off run with no install at all
uvx packsafe analyze requests
Use
packsafe analyze requests # verdict: score, checks, risk factors
packsafe inspect django -V 5.2.8 # every piece of evidence, with provenance
packsafe install --pip requests # gate, then install
packsafe install --uv requests # same, via uv
install is the part that matters. It refuses to install a package the policy blocks,
asks before installing one with warnings, and installs silently when it is safe:
| Result | What happens |
|---|---|
| No blocking signals | Installed |
| Warnings found | Prompts first (default: no). --yes for unattended use |
| Blocked by policy | Refused, exit code 4 |
Exit codes: 0 success · 1 not found or internal error · 2 registry unreachable ·
3 bad package data · 4 blocked by policy · 5 the package manager failed.
What it looks at
Evidence is collected from PyPI, OSV.dev, GitHub, deps.dev, CISA KEV and FIRST EPSS, then scored across five categories — security, integrity, supply chain, maintenance and adoption. Each score is accompanied by the checks that fired and the evidence behind them, so a number is never presented without a reason.
Every analysis records provenance: which source, which URL, when it was fetched, and the archive hash the verdict was computed against.
Under the hood
The scoring engine is deterministic and configuration-driven. The weight set, metrics and
gates live in scoring/config/*.yaml, and each run reports a SHA-256 over them so a score
can be reproduced or challenged later.
License
Apache-2.0
Metadata
Release files for packsafe 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| packsafe-0.1.0.tar.gz | 29.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| packsafe-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 67.2 kB
Release files / packsafe-0.1.0.tar.gz
| Download URL | packsafe-0.1.0.tar.gz |
|---|---|
| Size | 29.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5bbd84e39fb6f5c8883f84af02e8b63862697ab3b618d58798fc42c3a0c8e266
|
|
BLAKE2b-256 checksum How to use checksums |
90e1a0a01ec2c784ce3d8b74e241facfe12e7d3948221e15ab8a69d98aebd8b7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Omarchy","version":"4.0.4","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / packsafe-0.1.0-py3-none-any.whl
| Download URL | packsafe-0.1.0-py3-none-any.whl |
|---|---|
| Size | 37.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
acbc58c8dfe51056a3f175148dc0160912d4f9fc78fa6dfb0c7b701fc6dbecbd
|
|
BLAKE2b-256 checksum How to use checksums |
f0a99d6477712b15b569d849c2dd7e07c5e43ac80279b832cbb5d8d4c3e7ac1f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Omarchy","version":"4.0.4","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|