Skip to main content

pinhaul (Python SDK + CLI)

Runtime dependency security for vibe coders: one import (or one docker run with the agent) and Pinhaul knows exactly what your project actually runs, scans it, and tells you what matters in plain language.

Install

pip install pinhaul            # or: pip install "pinhaul[dotenv]" for .env loading

Quickstart

# 1. Get an API key
pinhaul register --email you@example.com

# 2. Add the key to your project
echo 'PINHAUL_API_KEY=<your key>' >> .env

# 3. One line in your app's entrypoint
from pinhaul import Pinhaul
Pinhaul(project_name="my-app", environment="prod", metadata={"team": "core"})

That's it. On startup, Pinhaul captures Python builtins (version, implementation, platform, script name, hostname) and the package versions actually loaded in your process — runtime truth, not a requirements.txt guess — and reports them to your Pinhaul cloud in a background thread that can never crash or block your app.

Snapshot caching (don't re-send what didn't change)

The SDK fingerprints the full payload (python facts + metadata + loaded inventory, sorted so import order doesn't matter) and caches it under ~/.cache/pinhaul/snapshots/. An unchanged environment within the TTL sends nothing; any change to python version, metadata, or a package version ships immediately. After the TTL (default 6h) the next start re-sends once as a liveness heartbeat — the server deduplicates that without creating rows.

Env var Default Effect
PINHAUL_REPORT_TTL 21600 (6h) Seconds an unchanged fingerprint is suppressed. 0 = always send
PINHAUL_NO_CACHE unset Set to disable client caching entirely

Pinhaul(..., force=True) bypasses the cache for one explicit send. Server-side dedup (same fingerprint within its window) protects against cache misses, CI, and second machines regardless of client settings. Check what happened via ds.last_result: sent / deduplicated / skipped / disabled.

What it sends (and never sends)

✅ python version/implementation, platform, script basename, hostname, loaded package names+versions, the metadata you explicitly pass.

❌ environment variables, file paths, source code, secrets, anything else.

Set PINHAUL_DISABLE=1 to no-op (e.g. in CI). Set PINHAUL_DEBUG=1 to print diagnostics to stderr on failure.

Local scan engines (feature-gated)

pinhaul scan --code                     # bandit SAST over your python code
pinhaul scan --secrets                  # gitleaks over your git history (full history, redacted)
pinhaul scan --code --secrets --project my-app
  • --code needs bandit: pip install "pinhaul[scan]"
  • --secrets needs the gitleaks binary on your PATH
  • Engines are enabled per plan server-side; a disabled engine prints 🔒 instead of running
  • Privacy: code snippets are never sent (bandit findings carry test id + file:line only); gitleaks runs with --redact and secret values are stripped client-side and server-side

CLI

pinhaul doctor [--docker]             # diagnose setup: API, key, cache, socket
pinhaul status                        # account + project health
pinhaul report [--project my-app]     # severity summary + dependency intel + AI insight
pinhaul findings [--severity critical,high] [--source trivy,osv,bandit,gitleaks,depintel]
pinhaul mute 7643 [7644 ...]          # hide accepted-risk findings from reports/alerts
pinhaul unmute 7643
pinhaul sbom --project my-app --out sbom.json   # CycloneDX 1.5 from runtime inventory
pinhaul analyze [--project my-app]    # queue an AI triage run
pinhaul init --name my-app            # print the integration snippet

API endpoint defaults to http://127.0.0.1:8000 for local development; override with PINHAUL_API_URL or --api-url.

Development

cd sdk && python3 -m venv .venv && . .venv/bin/activate
pip install -e . && python -m unittest discover tests -v

Metadata

Release files for pinhaul 0.4.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pinhaul 0.4.4
File Size Uploaded
pinhaul-0.4.4.tar.gz 18.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pinhaul 0.4.4
File Interpreter ABI Platform
pinhaul-0.4.4-py3-none-any.whl Python 3 none any Details

Total release size: 38.8 kB

Release files / pinhaul-0.4.4.tar.gz

Download URL pinhaul-0.4.4.tar.gz
Size 18.8 kB
Tags Source
SHA-256 checksum
How to use checksums
c92d4193816eecfa81cf4e60d394af7b320b11ebfc4e44a004d83aadd5644003
BLAKE2b-256 checksum
How to use checksums
e838ec77a0f5758d5c7e8607e54628c3512f9ac32224f5e53b16d41040b6d54b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / pinhaul-0.4.4-py3-none-any.whl

Download URL pinhaul-0.4.4-py3-none-any.whl
Size 20.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6de3c6c94125e079e257c6c440a1d4da5e0708d60f33bcf1d9196d344650bb13
BLAKE2b-256 checksum
How to use checksums
b6a2b86dee2ebfc5a4d3bbe55202072fbc77eb708e9ece80b85cb80129e624ff
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.0

2 release files

0.5.0

2 release files

0.4.5

2 release files

This release

0.4.4 This release

2 release files

0.4.3

2 release files

0.4.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page