pypiron
Host private packages and cache PyPI behind one ultra-fast index.
Get started · Deploy on cloud storage
- 100× faster than other self-hosted PyPI servers. 8,288 installs/s on 2 vCPU.
- Blocks 72% of malicious releases by default.
- Local disk, S3, GCS, and Azure.
- Scale without a database or coordinator. Add nodes to one bucket.
- Survives a region or cloud outage.
- Real clients. Real clouds. All 17 million PyPI files.
- Web dashboard with package pages and search.
- Health checks and Prometheus metrics built in.
Start pypiron
With uv installed,
replace your-admin-password and run:
PYPIRON_ADMIN_PASS='your-admin-password' uvx pypiron serve
pypiron is now running at http://localhost:8080. The admin username is
admin; the password is the one you chose.
Docker:
docker run -p 8080:8080 -e PYPIRON_ADMIN_PASS='your-admin-password' ghcr.io/blackthorn-interstellar/pypiron:latest
Publish and install packages · Deploy on cloud storage · Migrate from another server
Feature comparison
| Feature | pypiron | bandersnatch | pypiserver | pypicloud | devpi | proxpi | |
|---|---|---|---|---|---|---|---|
| Easy setup | ✅ | — | ✅ | — | — | ✅ | |
| Fast | ✅ | ✅ | — | — | — | — | |
| Private packages | ✅ | — | ✅ | ✅ | ✅ | — | |
| PyPI proxy | ✅ | — | — | ✅ | ✅ | ✅ | |
| Sync mirror | ✅ | ✅ | — | — | — | — | |
| Cooldown | ✅ | — | — | — | — | — | |
| Malware blocking | ✅ | — | — | — | — | — | |
| No dependency confusion | ✅ | — | — | — | ✅ | — | |
| Vulnerability audit | ✅ | — | — | — | — | — | |
| Scales, no database | ✅ | ✅ | — | — | — | — | |
| Multi-region failover | ✅ | — | — | — | ✅ | — | |
| Web GUI | ✅ | — | — | ✅ | ✅ | — | |
| Download stats | ✅ | — | — | — | — | — | |
| Storage | Disk | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| AWS S3 | ✅ | ✅ | — | ✅ | — | — | |
| GCS | ✅ | — | — | ✅ | — | — | |
| Azure Blob | ✅ | — | — | ✅ | — | — | |
Security
- Blocks known PyPI malware. OSV blocking plus a release cooldown.
- Private names stay private. They never fall through to public PyPI.
- Control which public packages install. Set one approval list for every client.
- Air-gapped deployments. Serve approved packages without internet access.
- Vulnerability audit. Affected public packages, ranked by downloads.
Gauntlet testing
- Eight real clients. uv, pip, poetry, pdm, pipenv, hatch, flit, and twine.
- Every PyPI file. All 17 million, checked against ground truth.
- Killed mid-write. Crash sweeps, fleet chaos, and hostile upstreams.
- Fuzzed nightly. Simulated and model-checked.
- Security-audited by frontier models. The same models that built it.
See the full testing gauntlet.
Going further
- Publish and install — private packages and the PyPI cache
- Deploy on cloud storage — S3, GCS, or Azure
- Migrate — move from pypicloud, devpi, Artifactory, or Nexus
- How pypiron works — storage, caching, access, and recovery
- Configuration — every flag and its
PYPIRON_*env var - Compare servers — benchmarks and when to choose something else
- For AI agents — decide, configure, and verify
Contributing — Humans Need Not Apply
pypiron was built by AI coding agents from Anthropic, OpenAI, SpaceXAI, and Moonshot — and that's how it stays. All development is done by AI coders, for security and consistency: human-developed code is a security risk, and we don't accept it. Humans are welcome to open issues and contribute documentation.
License
MIT — see LICENSE.
Release files for pypiron 0.0.23
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pypiron-0.0.23.tar.gz | 10.4 MB | Details |
Built distributions (wheels)
Total release size: 147.0 MB
Release files / pypiron-0.0.23.tar.gz
| Download URL | pypiron-0.0.23.tar.gz |
|---|---|
| Size | 10.4 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
da5b4f0194fd4f42e0d0ddf68f9c99ab249cc201ed8cbe63046648d34d6a227a
|
|
BLAKE2b-256 checksum How to use checksums |
4c2d68eb340ffe46b6071396aa0fd2f4ad841e5b7d6dc1754185b8ba8bf2e62b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-win_arm64.whl
| Download URL | pypiron-0.0.23-py3-none-win_arm64.whl |
|---|---|
| Size | 8.6 MB |
| Tags | Python 3 Windows ARM64 |
|
SHA-256 checksum How to use checksums |
680ca626faca1da49192810bc61934aa9f5ebf5ce62cd6a9d3887e7a510a381c
|
|
BLAKE2b-256 checksum How to use checksums |
36415d6093b39372c5920979769ba80d14b01743e1ed1061b0bd57c2363f9fd5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-win_amd64.whl
| Download URL | pypiron-0.0.23-py3-none-win_amd64.whl |
|---|---|
| Size | 9.0 MB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
63a7bda198196f03ab67e26966256b844223cef984afff6668fc60ae5238c137
|
|
BLAKE2b-256 checksum How to use checksums |
1a70acea459b466b87d6ebef800926c740865101f2c951564a141dbd98604384
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-win32.whl
| Download URL | pypiron-0.0.23-py3-none-win32.whl |
|---|---|
| Size | 7.9 MB |
| Tags | Python 3 Windows x86-32 |
|
SHA-256 checksum How to use checksums |
d9c2bd95dce1b37b446892c3216a1c069fb930c34dce554adbc16236977ca7e7
|
|
BLAKE2b-256 checksum How to use checksums |
b9c64f3044134e3bd284b0617de9d272aa67ea3ea21e7096cd9e30ad79f291a3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-musllinux_1_2_x86_64.whl
| Download URL | pypiron-0.0.23-py3-none-musllinux_1_2_x86_64.whl |
|---|---|
| Size | 9.2 MB |
| Tags | Linux musl 1.2+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
b0fcb9e50159fd66aa394b9762994cfe14f3718f1442e873cada7065edb6292f
|
|
BLAKE2b-256 checksum How to use checksums |
ffdd63d8d106e9819ca92298bccbc6e56d72527e114e5ed8e6e68135fdcbd380
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-musllinux_1_2_i686.whl
| Download URL | pypiron-0.0.23-py3-none-musllinux_1_2_i686.whl |
|---|---|
| Size | 8.6 MB |
| Tags | Linux musl 1.2+ x86-32 Python 3 |
|
SHA-256 checksum How to use checksums |
1473f213e69d3f4e78e1883e1258492098f96aa5f5d8251e255d89d82556dbb7
|
|
BLAKE2b-256 checksum How to use checksums |
c2c06df2ee0c80de6d42a130ae1ca8a4c2c0e2ec687b3a57a5e120114704ee6e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-musllinux_1_2_armv7l.whl
| Download URL | pypiron-0.0.23-py3-none-musllinux_1_2_armv7l.whl |
|---|---|
| Size | 8.1 MB |
| Tags | Linux musl 1.2+ ARMv7l Python 3 |
|
SHA-256 checksum How to use checksums |
c569e31c512d8f6a185d16a802bce68ee80c671f94200322229fe2a9bf356438
|
|
BLAKE2b-256 checksum How to use checksums |
1698c5315aea7fb059afa7df38ce7d2c68bd500c31bfa84146b64a4b0682c6bb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-musllinux_1_2_aarch64.whl
| Download URL | pypiron-0.0.23-py3-none-musllinux_1_2_aarch64.whl |
|---|---|
| Size | 8.5 MB |
| Tags | Linux musl 1.2+ ARM64 Python 3 |
|
SHA-256 checksum How to use checksums |
c02d6bd7a647745557ec23a3615cd0832208b16515c447d1c9fdd519c2d27843
|
|
BLAKE2b-256 checksum How to use checksums |
7a834b0b11bf5068c1eb895be7317566e1749303db1e18ea75462b1d4738d300
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-manylinux_2_31_riscv64.whl
| Download URL | pypiron-0.0.23-py3-none-manylinux_2_31_riscv64.whl |
|---|---|
| Size | 8.3 MB |
| Tags | Linux glibc 2.31+ RISC-V 64 Python 3 |
|
SHA-256 checksum How to use checksums |
b16daefa712264cf1f4d66b9fa8ae1a42f7f26a25200d7c23c6b1bb284aad008
|
|
BLAKE2b-256 checksum How to use checksums |
fbe2c2757901d6dc2649e357889b4bf5222035871a20012909e0dcb9e5f11b31
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-manylinux_2_28_ppc64le.whl
| Download URL | pypiron-0.0.23-py3-none-manylinux_2_28_ppc64le.whl |
|---|---|
| Size | 8.9 MB |
| Tags | Linux glibc 2.28+ PowerPC 64-le Python 3 |
|
SHA-256 checksum How to use checksums |
50016fef639580fabd9e6d7a05ddfbb4a3e3fb9a0bb5c5b24e37ea468d1069dd
|
|
BLAKE2b-256 checksum How to use checksums |
c1d668bc75e747501fc70b6c83b17714ff46140a6b790098b1eedf43e9c175ec
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | pypiron-0.0.23-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 9.0 MB |
| Tags | Linux glibc 2.17+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
4f276c5dd37857eefb8d850ec3e238f97afa4f4e3f1644502e31790fbd5a788e
|
|
BLAKE2b-256 checksum How to use checksums |
7427d008106e9928178392ee9ae73602b0a420769194a4131bd2a7ce8789b497
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-manylinux_2_17_s390x.manylinux2014_s390x.whl
| Download URL | pypiron-0.0.23-py3-none-manylinux_2_17_s390x.manylinux2014_s390x.whl |
|---|---|
| Size | 8.6 MB |
| Tags | Linux glibc 2.17+ IBM System/390x Python 3 |
|
SHA-256 checksum How to use checksums |
c295b16364a5d98f8111f7257c74eac2b19ea791336bec8bfdefbd9335b140d4
|
|
BLAKE2b-256 checksum How to use checksums |
bfe13733831c5f727a65e794899bc0f91d9853f4fb67b8fdd81dd12e85d31ef9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-manylinux_2_17_i686.manylinux2014_i686.whl
| Download URL | pypiron-0.0.23-py3-none-manylinux_2_17_i686.manylinux2014_i686.whl |
|---|---|
| Size | 8.8 MB |
| Tags | Linux glibc 2.17+ x86-32 Python 3 |
|
SHA-256 checksum How to use checksums |
165a5a21a0a2f5d7a833466d9bd063c3f96d86ad11ee7f2642e333511dc9cd96
|
|
BLAKE2b-256 checksum How to use checksums |
00b749527ba4d982b214b1489b154072572352bf3e7753fccf9e6ba4e471a7ba
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-manylinux_2_17_armv7l.manylinux2014_armv7l.whl
| Download URL | pypiron-0.0.23-py3-none-manylinux_2_17_armv7l.manylinux2014_armv7l.whl |
|---|---|
| Size | 8.1 MB |
| Tags | Linux glibc 2.17+ ARMv7l Python 3 |
|
SHA-256 checksum How to use checksums |
20de7eff8e7d738b3d2badfd029caeab0bde90e0844b9ebca3de46bd02451ede
|
|
BLAKE2b-256 checksum How to use checksums |
dcf8f2fd1f8d094f878134cc9488778b952f778d60913bd0b0b9fbe0b5b58d94
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | pypiron-0.0.23-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 8.5 MB |
| Tags | Linux glibc 2.17+ ARM64 Python 3 |
|
SHA-256 checksum How to use checksums |
601640e3fa26bd87f54023761502990a4d4ef1b4f17a849baa959844c329459a
|
|
BLAKE2b-256 checksum How to use checksums |
cbe27e91c52e74916e6efea117286bd321a5a6eea8c63086e48de4dab6bad10c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-macosx_11_0_arm64.whl
| Download URL | pypiron-0.0.23-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 7.7 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
bf28a2bd89dc42a7237dabdfa72ca2cf6c17c71c254e513f9f1305b21f963805
|
|
BLAKE2b-256 checksum How to use checksums |
78250c2a0cd3c0f93b1b016bf2026a5d72ba5c8863dbc0f6b437cc0f9e42e201
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / pypiron-0.0.23-py3-none-macosx_10_12_x86_64.whl
| Download URL | pypiron-0.0.23-py3-none-macosx_10_12_x86_64.whl |
|---|---|
| Size | 8.9 MB |
| Tags | Python 3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
ae69dc673a05cc74564787f8fa3b1d83c08561d9bd95e6878a0bee0c53c2b43e
|
|
BLAKE2b-256 checksum How to use checksums |
102a79db0fba8453baa91932ddaeadd0d7ab104bc4f418e06d315d5d445ce3f0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency log