Skip to main content

pinhaul (Python SDK + CLI)

Runtime dependency security for vibe coders: one import (or one docker run with the agent) and Pinhaul knows exactly what your project actually runs, scans it, and tells you what matters in plain language.

Install

pip install pinhaul            # or: pip install "pinhaul[dotenv]" for .env loading

Quickstart

# 1. Get an API key
pinhaul register --email you@example.com

# 2. Add the key to your project
echo 'PINHAUL_API_KEY=<your key>' >> .env

# 3. One line in your app's entrypoint
from pinhaul import Pinhaul
Pinhaul(project_name="my-app", environment="prod", metadata={"team": "core"})

That's it. On startup, Pinhaul captures Python builtins (version, implementation, platform, script name, hostname) and the package versions actually loaded in your process — runtime truth, not a requirements.txt guess — and reports them to your Pinhaul cloud in a background thread that can never crash or block your app.

Snapshot caching (don't re-send what didn't change)

The SDK fingerprints the full payload (python facts + metadata + loaded inventory, sorted so import order doesn't matter) and caches it under ~/.cache/pinhaul/snapshots/. An unchanged environment within the TTL sends nothing; any change to python version, metadata, or a package version ships immediately. After the TTL (default 6h) the next start re-sends once as a liveness heartbeat — the server deduplicates that without creating rows.

Env var Default Effect
PINHAUL_REPORT_TTL 21600 (6h) Seconds an unchanged fingerprint is suppressed. 0 = always send
PINHAUL_NO_CACHE unset Set to disable client caching entirely

Pinhaul(..., force=True) bypasses the cache for one explicit send. Server-side dedup (same fingerprint within its window) protects against cache misses, CI, and second machines regardless of client settings. Check what happened via ds.last_result: sent / deduplicated / skipped / disabled.

What it sends (and never sends)

✅ python version/implementation, platform, script basename, hostname, loaded package names+versions, the metadata you explicitly pass.

❌ environment variables, file paths, source code, secrets, anything else.

Set PINHAUL_DISABLE=1 to no-op (e.g. in CI). Set PINHAUL_DEBUG=1 to print diagnostics to stderr on failure.

Local scan engines (feature-gated)

pinhaul scan --code                     # bandit SAST over your python code
pinhaul scan --secrets                  # gitleaks over your git history (full history, redacted)
pinhaul scan --code --secrets --project my-app
  • --code needs bandit: pip install "pinhaul[scan]"
  • --secrets needs the gitleaks binary on your PATH
  • Engines are enabled per plan server-side; a disabled engine prints 🔒 instead of running
  • Privacy: code snippets are never sent (bandit findings carry test id + file:line only); gitleaks runs with --redact and secret values are stripped client-side and server-side

CLI

pinhaul doctor [--docker]             # diagnose setup: API, key, cache, socket
pinhaul status                        # account + project health
pinhaul report [--project my-app]     # severity summary + dependency intel + AI insight
pinhaul findings [--severity critical,high] [--source trivy,osv,bandit,gitleaks,depintel]
pinhaul mute 7643 [7644 ...]          # hide accepted-risk findings from reports/alerts
pinhaul unmute 7643
pinhaul sbom --project my-app --out sbom.json   # CycloneDX 1.5 from runtime inventory
pinhaul analyze [--project my-app]    # queue an AI triage run
pinhaul init --name my-app            # print the integration snippet

API endpoint defaults to http://127.0.0.1:8000 for local development; override with PINHAUL_API_URL or --api-url.

Development

cd sdk && python3 -m venv .venv && . .venv/bin/activate
pip install -e . && python -m unittest discover tests -v

Metadata

Release files for pinhaul 0.4.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pinhaul 0.4.5
File Size Uploaded
pinhaul-0.4.5.tar.gz 18.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pinhaul 0.4.5
File Interpreter ABI Platform
pinhaul-0.4.5-py3-none-any.whl Python 3 none any Details

Total release size: 38.8 kB

Release files / pinhaul-0.4.5.tar.gz

Download URL pinhaul-0.4.5.tar.gz
Size 18.8 kB
Tags Source
SHA-256 checksum
How to use checksums
59988df99cb0758184715491195c5f47c8085376d3ea3ae16e37e142041eee97
BLAKE2b-256 checksum
How to use checksums
4d0d7d3efa0ea75888a91d92928898674091eed11f54dfcd0237f37c26a2ea8e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / pinhaul-0.4.5-py3-none-any.whl

Download URL pinhaul-0.4.5-py3-none-any.whl
Size 20.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b03a242100cee5c8edf93c522a585264055ce32a2a2aadbed787fdf09ebe9961
BLAKE2b-256 checksum
How to use checksums
8ca86670c0ed7828dc9a40d20d2f05904cc7b99b0b96906aa1312c0dcbf878f1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.0

2 release files

0.5.0

2 release files

This release

0.4.5 This release

2 release files

0.4.4

2 release files

0.4.3

2 release files

0.4.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page