Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

poetry-restrict-plugin

This Poetry plugin aims to restrict Poetry's allowed accesses to what it needs to fulfill its function, the goal is to apply principle of least privilege to our development tooling.

Motivation

What's the worst thing that could happen if you install a malicious Python dependency on your computer? Which information could it gather from your files, and how could it make itself a permanent home on your computer?

With poetry-restrict-plugin, that looks as follows:

$ poetry run cat ~/.ssh/config
poetry-restrict-plugin: Landlock engaged.
cat: /home/jc/.ssh/config: Permission denied
$ poetry run ls ~/.ssh
poetry-restrict-plugin: Landlock engaged.
ls: cannot open directory '/home/jc/.ssh': Permission denied

Installation

poetry-restrict-plugin is currently only supported on Linux with the Landlock LSM enabled.

Installation depends on how you installed Poetry. With pipx:

pipx inject poetry poetry-restrict-plugin

Alternatively, you can install it with poetry self add:

poetry self add poetry-restrict-plugin

See poetry self add --help for more options for installation, including installing development versions.

For other installation methods, see the Poetry plugin documentation.

Usage

The plugin will automatically run whenever you invoke poetry. If you run into an error with it and need an escape hatch, you can re-run your command with the environment variable POETRY_NO_RESTRICT=1 set.

Disclaimer

poetry-restrict-plugin is not a perfect sandbox, and probably never will be. If you're looking for something like that, nsjail might be interesting for you.

License

poetry-restrict-plugin is free software; you can redistribute it and/or modify it under the terms of the GNU Lesser General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.

poetry-restrict-plugin is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.

You should have received a copy of the GNU Lesser General Public License along with poetry-restrict-plugin; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.

Release files for poetry-restrict-plugin 0.1.0a7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for poetry-restrict-plugin 0.1.0a7
File Size Uploaded
poetry_restrict_plugin-0.1.0a7.tar.gz 7.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for poetry-restrict-plugin 0.1.0a7
File Interpreter ABI Platform
poetry_restrict_plugin-0.1.0a7-py3-none-any.whl Python 3 none any Details

Total release size: 15.5 kB

Release files / poetry_restrict_plugin-0.1.0a7.tar.gz

Download URL poetry_restrict_plugin-0.1.0a7.tar.gz
Size 7.2 kB
Tags Source
SHA-256 checksum
How to use checksums
b568131b373abd6073de566b5eb5ac1a522369de694b02fc1b9d6acf5a0e196d
BLAKE2b-256 checksum
How to use checksums
d34008b9823fd0c63d498d6ef6e81dd83dedaaaabf27cc4d3e50afcb7ee79784
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.8.3 CPython/3.11.2 Linux/6.1.0-23-amd64

Release files / poetry_restrict_plugin-0.1.0a7-py3-none-any.whl

Download URL poetry_restrict_plugin-0.1.0a7-py3-none-any.whl
Size 8.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
614b1648bb7e23df55e1842bae46c3ba6e82d960b680655777d00e663eb6f731
BLAKE2b-256 checksum
How to use checksums
a460e20a713d3ca773314e9181ac1e4e95eac175866876768af27d68bd66acb5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.8.3 CPython/3.11.2 Linux/6.1.0-23-amd64
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page