pinhaul (Python SDK + CLI)
Runtime dependency security for vibe coders: one import (or one docker run with the
agent) and Pinhaul knows exactly what your project actually runs, scans it,
and tells you what matters in plain language.
Install
pip install pinhaul # or: pip install "pinhaul[dotenv]" for .env loading
Quickstart
# 1. Get an API key
pinhaul register --email you@example.com
# 2. Add the key to your project
echo 'PINHAUL_API_KEY=<your key>' >> .env
# 3. One line in your app's entrypoint
from pinhaul import Pinhaul
Pinhaul(project_name="my-app", environment="prod", metadata={"team": "core"})
That's it. On startup, Pinhaul captures Python builtins (version, implementation, platform, script name, hostname) and the package versions actually loaded in your process — runtime truth, not a requirements.txt guess — and reports them to your Pinhaul cloud in a background thread that can never crash or block your app.
Snapshot caching (don't re-send what didn't change)
The SDK fingerprints the full payload (python facts + metadata + loaded inventory,
sorted so import order doesn't matter) and caches it under
~/.cache/pinhaul/snapshots/. An unchanged environment within the TTL sends
nothing; any change to python version, metadata, or a package version ships
immediately. After the TTL (default 6h) the next start re-sends once as a liveness
heartbeat — the server deduplicates that without creating rows.
| Env var | Default | Effect |
|---|---|---|
PINHAUL_REPORT_TTL |
21600 (6h) |
Seconds an unchanged fingerprint is suppressed. 0 = always send |
PINHAUL_NO_CACHE |
unset | Set to disable client caching entirely |
Pinhaul(..., force=True) bypasses the cache for one explicit send. Server-side
dedup (same fingerprint within its window) protects against cache misses, CI, and
second machines regardless of client settings. Check what happened via
ds.last_result: sent / deduplicated / skipped / disabled.
What it sends (and never sends)
✅ python version/implementation, platform, script basename, hostname, loaded package names+versions, the metadata you explicitly pass.
❌ environment variables, file paths, source code, secrets, anything else.
Set PINHAUL_DISABLE=1 to no-op (e.g. in CI). Set PINHAUL_DEBUG=1 to print
diagnostics to stderr on failure.
Local scan engines (feature-gated)
pinhaul scan --code # bandit SAST over your python code
pinhaul scan --secrets # gitleaks over your git history (full history, redacted)
pinhaul scan --code --secrets --project my-app
--codeneeds bandit:pip install "pinhaul[scan]"--secretsneeds the gitleaks binary on your PATH- Engines are enabled per plan server-side; a disabled engine prints 🔒 instead of running
- Privacy: code snippets are never sent (bandit findings carry test id + file:line only);
gitleaks runs with
--redactand secret values are stripped client-side and server-side
CLI
pinhaul doctor [--docker] # diagnose setup: API, key, cache, socket
pinhaul status # account + project health
pinhaul report [--project my-app] # severity summary + dependency intel + AI insight
pinhaul findings [--severity critical,high] [--source trivy,osv,bandit,gitleaks,depintel]
pinhaul mute 7643 [7644 ...] # hide accepted-risk findings from reports/alerts
pinhaul unmute 7643
pinhaul sbom --project my-app --out sbom.json # CycloneDX 1.5 from runtime inventory
pinhaul analyze [--project my-app] # queue an AI triage run
pinhaul init --name my-app # print the integration snippet
API endpoint defaults to http://127.0.0.1:8000 for local development; override with
PINHAUL_API_URL or --api-url.
Development
cd sdk && python3 -m venv .venv && . .venv/bin/activate
pip install -e . && python -m unittest discover tests -v
Metadata
Release files for pinhaul 0.4.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pinhaul-0.4.4.tar.gz | 18.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pinhaul-0.4.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 38.8 kB
Release files / pinhaul-0.4.4.tar.gz
| Download URL | pinhaul-0.4.4.tar.gz |
|---|---|
| Size | 18.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c92d4193816eecfa81cf4e60d394af7b320b11ebfc4e44a004d83aadd5644003
|
|
BLAKE2b-256 checksum How to use checksums |
e838ec77a0f5758d5c7e8607e54628c3512f9ac32224f5e53b16d41040b6d54b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency logRelease files / pinhaul-0.4.4-py3-none-any.whl
| Download URL | pinhaul-0.4.4-py3-none-any.whl |
|---|---|
| Size | 20.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6de3c6c94125e079e257c6c440a1d4da5e0708d60f33bcf1d9196d344650bb13
|
|
BLAKE2b-256 checksum How to use checksums |
b6a2b86dee2ebfc5a4d3bbe55202072fbc77eb708e9ece80b85cb80129e624ff
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.
Transparency log