Skip to main content

pipguard logo

pipguard

PyPI - Version codecov Documentation Python Version

Python supply chain security tool. Scan packages before installing them.

AST-based static analysis + known CVE lookup via osv.dev.

pip install pipguard
pipguard install litellm==1.82.8   # Blocks the March 2026 attack. Exits 1.

Zero configuration. Zero external dependencies. Pure stdlib.

pipguard demo


The Problem

The March 2026 litellm attack (97M downloads/month) embedded Python code in a .pth file — executed automatically at interpreter startup, exfiltrating SSH keys, AWS credentials, and Kubernetes configs from a single pip install.

Classical tools (pip-audit, GuardDog) are blind to zero-day attacks. They check known signatures. pipguard asks a different question:

Should any pip install be allowed to read ~/.ssh/id_rsa?

The answer is no. And that question doesn't require a database.

Installation

Install pipguard outside your project's virtualenv — this prevents untrusted package code from tampering with the scanner itself.

# Recommended: isolated, persistent install
pipx install pipguard

# CI / one-off use (no pre-install needed)
uvx pipguard install -r requirements.txt

# Standard
pip install pipguard

Usage

# Install a single package
pipguard install requests

# Install from requirements.txt
pipguard install -r requirements.txt

# CI mode: never prompts, exits 1 on CRITICAL/HIGH
pipguard install --yes -r requirements.txt

# Allow a known-legitimate package that accesses credentials
pipguard install --allow paramiko -r requirements.txt

# Override for known false-positives (use with care)
pipguard install --force my-trusted-internal-pkg

# Show full LOW/CLEAN scan details
pipguard install --verbose requests

# Show raw pip install output
pipguard install --show-pip-output requests

By default, pipguard prints a risk summary, expands CRITICAL / HIGH / MEDIUM, collapses LOW to package-level counts, and keeps successful pip install logs quiet. Use --verbose for full scan details and --show-pip-output to restore raw pip logs.

For the full reference — risk levels, exit codes, allowlist, and CI integration — see the documentation.

CI Integration

GitHub Actions

Use the bundled composite action to gate installs in a workflow — it fails the job on CRITICAL/HIGH findings:

- uses: shenxianpeng/pipguard@v0.2.0
  with:
    requirements: requirements.txt
    check-vulns: true        # also query OSV.dev for known CVEs (optional)

Or scan explicit packages:

- uses: shenxianpeng/pipguard@v0.2.0
  with:
    packages: "requests numpy==1.26.3"

pre-commit

Add pipguard to .pre-commit-config.yaml to scan your requirements file before every commit that changes it:

repos:
  - repo: https://github.com/shenxianpeng/pipguard
    rev: v0.2.0
    hooks:
      - id: pipguard
        # scans requirements.txt by default; override for a different file:
        # args: ['-r', 'requirements/prod.txt']

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pipguard-0.4.1.tar.gz (400.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pipguard-0.4.1-py3-none-any.whl (37.3 kB view details)

Uploaded Python 3

File details

Details for the file pipguard-0.4.1.tar.gz.

File metadata

  • Download URL: pipguard-0.4.1.tar.gz
  • Upload date:
  • Size: 400.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pipguard-0.4.1.tar.gz
Algorithm Hash digest
SHA256 d0298ea00dee8239695e1d5e7ca989d2ac05a323b6595205ec92b1e5c93e4480
MD5 8dddf930932fd438b20b0afb3a57905d
BLAKE2b-256 0bc8a1e7bbadf22891299aff01a2b4bb9a37bd063624e656fd9c937c15691d29

See more details on using hashes here.

Provenance

The following attestation bundles were made for pipguard-0.4.1.tar.gz:

Publisher: publish.yml on shenxianpeng/pipguard

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pipguard-0.4.1-py3-none-any.whl.

File metadata

  • Download URL: pipguard-0.4.1-py3-none-any.whl
  • Upload date:
  • Size: 37.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pipguard-0.4.1-py3-none-any.whl
Algorithm Hash digest
SHA256 2e2632d90afa9eaa6d78994384cac336e16df07c32f83c8b0ee0e61dde733bee
MD5 2e5bdd82493c2ed01c815a2e1f7bbc40
BLAKE2b-256 97f7dcaa1f3cec02823198ebc58cf2d3c6d57d9ff45420ca7c7d26df7cde5c48

See more details on using hashes here.

Provenance

The following attestation bundles were made for pipguard-0.4.1-py3-none-any.whl:

Publisher: publish.yml on shenxianpeng/pipguard

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page