Skip to main content

RFFickle: Roboflow Fork of Fickle

This is a fork of the Fickle package by Eduard Christian Dumitrescu, with additional functionality added by Roboflow.

Fork Information

  • Original Package: fickle v0.2.2
  • Original Author: Eduard Christian Dumitrescu
  • Fork Maintainer: Roboflow, Inc.
  • PyPI Package: rffickle

This fork was created from the PyPI source distribution as the original source code was not available on GitHub.


Original README: Fickle - Firewalled Pickle

People abuse pickle. Especially researchers. Pickle is not secure. Published datasets and ML training weights are often distributed as pickle files (or formats which use pickle files, such as PyTorch checkpoint.ckpt files). Sometimes it is the only format that they are available in.

Examples

Loading basic types is easy:

>>> from fickle import DefaultFirewall
>>> import pickle
>>>
>>> my_picked_data = pickle.dumps({"list": [1, 2, "three", b"four"]})
>>>
>>> firewall = DefaultFirewall()
>>> firewall.loads(my_picked_data)
{'list': [1, 2, 'three', b'four']}

Safely loading PyTorch checkpoint files into numpy arrays is just as easy:

>>> from fickle.ext.pytorch import fake_torch_load_zipped
>>> from zipfile import ZipFile
>>>
>>> zf = ZipFile("/path/to/sd-v1-4.ckpt")
>>> ckpt = fake_torch_load_zipped(zf)
>>> tensor = ckpt["state_dict"]["model.diffusion_model.output_blocks.3.1.norm.weight"]
>>> tensor.array
array([0.39097363, 0.3898967 , 0.35191917, ..., 0.41924757, 0.4031702 ,
       0.37156993], dtype=float32)

You can, optionally, even use marshmallow for validation!

Alternatives

fickle picklemagic pikara
Does not rely on pickle._Unpickler? ✅ ❌ ✅
Uses pickletools.genops yes no yes
Can load without executing? ✅ ✅ ?
Forbid importing arbitrary objects? ✅ ✅ ?
Forbid calling list.append/set.add/etc? ✅ ❌ ?
Forbid calling all methods by default? ✅ ❌ ?
Can create dangerous circular structures? ✅ ✅ ?
Safe against billion laughs DoS attack? ? ? ?
Full support for all pickle opcodes? ❌ ✅ ?
Has unit tests? ✅ ❌ ✅
Stable API? ❌ ✅ ✅

Metadata

Release files for rffickle 0.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rffickle 0.2.2
File Size Uploaded
rffickle-0.2.2.tar.gz 18.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rffickle 0.2.2
File Interpreter ABI Platform
rffickle-0.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 35.1 kB

Release files / rffickle-0.2.2.tar.gz

Download URL rffickle-0.2.2.tar.gz
Size 18.2 kB
Tags Source
SHA-256 checksum
How to use checksums
67cd9d9b964f7ced51562fbc4c5a5a35eb3bb21f5e9c73573e597025f3c69e5a
BLAKE2b-256 checksum
How to use checksums
7e45f9de363cfbcc257b751571788e7d37f4175406bf14983797f386d89f900b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 29, 2025.

Transparency log

Release files / rffickle-0.2.2-py3-none-any.whl

Download URL rffickle-0.2.2-py3-none-any.whl
Size 16.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2459979c1e1025feff38f9f708e6328a6263fe2df359692bcd24c2e5fad9cef5
BLAKE2b-256 checksum
How to use checksums
2d37a3240d76c2723a89332aa73a9a917d69e4d0945a90050d315bb7759e2ac9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 29, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page