Package to check if private repository libraries have a public doppelgaenger with the same name. The goal is to prevent a dependency confusion attack on the PyPi ecosystem.
Project description
Package to check if private repository libraries have a public doppelgaenger with the same name. The goal is to prevent a dependency confusion attack on the PyPi ecosystem.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
pvpcheck-1.1.0.tar.gz
(2.6 kB
view details)
File details
Details for the file pvpcheck-1.1.0.tar.gz.
File metadata
- Download URL: pvpcheck-1.1.0.tar.gz
- Upload date:
- Size: 2.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.9.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
36541fd6e7bbf3ce3e02470b944b5d120a15e2daad742d278577368fe7627e78
|
|
| MD5 |
a4602db01698bf6dbf314097ec456f5b
|
|
| BLAKE2b-256 |
1b3518df51e56e0fa0c02a93ca44773ea8a60c19d5f17e9204e9e744df6b8da7
|