Skip to main content

Scan Python packages for supply chain attacks before installing them

Project description

pipguard logo

pipguard

PyPI - Version codecov Documentation Python Version

Python supply chain security tool. Scan packages before installing them.

pip install pipguard
pipguard install litellm==1.82.8   # Blocks the March 2026 attack. Exits 1.

Zero configuration. Zero external dependencies. Pure stdlib.

pipguard demo


The Problem

The March 2026 litellm attack (97M downloads/month) embedded Python code in a .pth file — executed automatically at interpreter startup, exfiltrating SSH keys, AWS credentials, and Kubernetes configs from a single pip install.

Classical tools (pip-audit, GuardDog) are blind to zero-day attacks. They check known signatures. pipguard asks a different question:

Should any pip install be allowed to read ~/.ssh/id_rsa?

The answer is no. And that question doesn't require a database.

Installation

Install pipguard outside your project's virtualenv — this prevents untrusted package code from tampering with the scanner itself.

# Recommended: isolated, persistent install
pipx install pipguard

# CI / one-off use (no pre-install needed)
uvx pipguard install -r requirements.txt

# Standard
pip install pipguard

Usage

# Install a single package
pipguard install requests

# Install from requirements.txt
pipguard install -r requirements.txt

# CI mode: never prompts, exits 1 on CRITICAL/HIGH
pipguard install --yes -r requirements.txt

# Allow a known-legitimate package that accesses credentials
pipguard install --allow paramiko -r requirements.txt

# Override for known false-positives (use with care)
pipguard install --force my-trusted-internal-pkg

For the full reference — risk levels, exit codes, allowlist, and CI integration — see the documentation.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pipguard-0.3.0.tar.gz (353.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pipguard-0.3.0-py3-none-any.whl (23.0 kB view details)

Uploaded Python 3

File details

Details for the file pipguard-0.3.0.tar.gz.

File metadata

  • Download URL: pipguard-0.3.0.tar.gz
  • Upload date:
  • Size: 353.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pipguard-0.3.0.tar.gz
Algorithm Hash digest
SHA256 e67495efb245e9987bab874f89a850161c8d0b42b88b12bf8676c74a6360c701
MD5 0d34bf92f24a313c27eec5b60f7fc56e
BLAKE2b-256 95faf21a60370381b11a5e0400ded5c6bbb4a1d7f1a529e4559ebec16fafdbbb

See more details on using hashes here.

Provenance

The following attestation bundles were made for pipguard-0.3.0.tar.gz:

Publisher: publish.yml on shenxianpeng/pipguard

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pipguard-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: pipguard-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 23.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pipguard-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9ec8391c6bee477680f4cf0fbb74690a7ae7db83ecf65531b95d16ce81ad6238
MD5 663a30354c3c1a9c8e502d1909a84619
BLAKE2b-256 da3e129f3aba7c4510a8d41f1cb30944db1b3278437cc48622bfd0466eb7b3a5

See more details on using hashes here.

Provenance

The following attestation bundles were made for pipguard-0.3.0-py3-none-any.whl:

Publisher: publish.yml on shenxianpeng/pipguard

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page