Skip to main content

Package to check if private repository libraries have a public doppelgaenger with the same name. The goal is to prevent a dependency confusion attack on the PyPi ecosystem.

Project description

Package to check if private repository libraries have a public doppelgaenger with the same name. The goal is to prevent a dependency confusion attack on the PyPi ecosystem.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pvpcheck-1.1.0.tar.gz (2.6 kB view details)

Uploaded Source

File details

Details for the file pvpcheck-1.1.0.tar.gz.

File metadata

  • Download URL: pvpcheck-1.1.0.tar.gz
  • Upload date:
  • Size: 2.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.9.12

File hashes

Hashes for pvpcheck-1.1.0.tar.gz
Algorithm Hash digest
SHA256 36541fd6e7bbf3ce3e02470b944b5d120a15e2daad742d278577368fe7627e78
MD5 a4602db01698bf6dbf314097ec456f5b
BLAKE2b-256 1b3518df51e56e0fa0c02a93ca44773ea8a60c19d5f17e9204e9e744df6b8da7

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page