Skip to main content

Zero-config install-time supply-chain hardening for npm, pnpm, yarn, bun, cargo, mise, and uv.

Project description

pmsec (Python)

Zero-config install-time supply-chain hardening for npm, pnpm, yarn, bun, cargo, mise, and uv. One command flips on every safe-by-default knob each package manager exposes — install cooldown, signature trust policy, lockfile re-verification, build-script attestation, and more.

Install

uvx pmsec enable
uvx pmsec check
uvx pmsec disable
npx pmsec enable
npx pmsec check
npx pmsec disable

If your environment already enforces cooldown (or routes through a proxy index), bootstrap pmsec by overriding just for that call:

uvx --index https://pypi.org/simple --exclude-newer-package pmsec=2099-01-01 pmsec check
npx --registry=https://registry.npmjs.org/ --min-release-age=0 pmsec check

Supported tools

npm, pnpm, yarn 4+, bun, cargo (RFC #3801), mise, uv

Commands

Command Description
pmsec enable Write the hardening bundle (3-day cooldown + per-tool extras) to every selected tool's user config
pmsec check Read each tool's config; exit 1 if any row is missing or below the bundled value
pmsec disable Remove every key the bundle set; other keys in the file are preserved
pmsec --version Print the installed pmsec version

Options: --tool npm,pnpm,yarn,bun,cargo,mise,uv, --days N (override the 3-day default), --force (overwrite stricter existing cooldowns; default is monotonic), --json.

See the project README for the full table of keys, units, paths, and overrides.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pmsec-0.5.2.tar.gz (11.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pmsec-0.5.2-py3-none-any.whl (17.1 kB view details)

Uploaded Python 3

File details

Details for the file pmsec-0.5.2.tar.gz.

File metadata

  • Download URL: pmsec-0.5.2.tar.gz
  • Upload date:
  • Size: 11.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pmsec-0.5.2.tar.gz
Algorithm Hash digest
SHA256 84cb65b71e41ba4e14c0da31e82e01256366f016333bda4701db510b8471e4ab
MD5 b72e0bbd91735c613ef0f653c4f72417
BLAKE2b-256 d8a90bad02c9ef8493c25cce4b548f82c4a2335bf9c4115084b5c944537bfc90

See more details on using hashes here.

Provenance

The following attestation bundles were made for pmsec-0.5.2.tar.gz:

Publisher: pmsec-release-pypi.yml on HikaruEgashira/pmsec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file pmsec-0.5.2-py3-none-any.whl.

File metadata

  • Download URL: pmsec-0.5.2-py3-none-any.whl
  • Upload date:
  • Size: 17.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for pmsec-0.5.2-py3-none-any.whl
Algorithm Hash digest
SHA256 1e0b92b2d911086629e9f24d87494f74d353df08430072c548e7f74c3318245a
MD5 9d4f52ea8bd81c4edb1242c01a2b255a
BLAKE2b-256 53e467ac38b2c0eff3fb86ee76b3a201a509c4c6342d2d3f6b435cb2fb7da6fa

See more details on using hashes here.

Provenance

The following attestation bundles were made for pmsec-0.5.2-py3-none-any.whl:

Publisher: pmsec-release-pypi.yml on HikaruEgashira/pmsec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page