Skip to main content

A defensive pip wrapper with supply-chain preflight checks.

Project description

Not Finished Yet. Contribution Welcome. Site at https://spip.lamentxu.top/

secured_pip

Test License: GPL v3 Codecov

An open-source, free guard for your pip to avoid supply-chain attacks.

By using this, you can avoid being screwed by the poisoned LiteLLM, etc. just because you type pip install

What?

Currently, supply chain attacks are one of the major security concerns all over the world. The secured_pip project is a future pip wrapper focused on supply-chain risk controls.

Wait, What?

You can use

spip install requests

Instead of

pip install requests

To install a package more safely in the scope of supply chain security.

You do not need to configure. You do not need to learn. Just pure install-to-master.

In other words, you can completely replace pip install with spip install to make your installation safer :)

If you want a near drop-in experience, you can set a shell alias from pip to spip.

PowerShell (Windows):

if (!(Test-Path $PROFILE)) { New-Item -Type File -Path $PROFILE -Force }
Add-Content $PROFILE 'function pip { spip @args }'
. $PROFILE

Bash (Linux):

echo "alias pip='spip'" >> ~/.bashrc
source ~/.bashrc

Zsh (macOS):

echo "alias pip='spip'" >> ~/.zshrc
source ~/.zshrc

The secured_pip project will actively check for all the supply chain risks and avoid you installing potentially malicious packages when typing spip install

Except for the install commands, the project behaves exactly the same as the original pip program. That is, you can always use spip instead of pip in any case :)

Current minimum Python version: 3.10

We currently have three install warning policies:

  • HIGH: pause installation and require --ignore-warning
  • MEDIUM: prompt y/n before continuing
  • LOW: warn and continue

When spip detects a potential risk, a warning will be raised, with the level depending on the severity the risk is.

For now, the project has several major check points:

  • Fake typo checks: Hackers often use "fake typos" to inject a malicious dependency package into the poisoned source file. spip detects this by first resolving all the packages that pip install is going to download, and then comparing non-popular resolved package names with a local hot-package list. Warning levels:
    • Medium severity: requsets vs requests
    • Medium severity: pandaz vs pandas
    • Low severity: sixth vs six
  • Fresh release checks: If the selected PyPI release was published less than 2 days ago, spip will raise a MEDIUM warning.
  • Zero-version checks: If the selected package version is 0.0 or 0.0.0, spip will raise a LOW warning.
  • .pth file detection: Instead of directly injecting malicious code inside the package, today most hackers will place their bad stuff under a .pth file, with an import as the beginning. spip only checks the installed file-system diff after installation. The warning level is always MEDIUM, and spip will ask whether to delete the suspicious installed .pth file.
  • TODO ...

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

secured_pip-0.1.0.tar.gz (40.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

secured_pip-0.1.0-py3-none-any.whl (34.9 kB view details)

Uploaded Python 3

File details

Details for the file secured_pip-0.1.0.tar.gz.

File metadata

  • Download URL: secured_pip-0.1.0.tar.gz
  • Upload date:
  • Size: 40.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0b2

File hashes

Hashes for secured_pip-0.1.0.tar.gz
Algorithm Hash digest
SHA256 45e231937b2edcd0f7293a60ca5b1385f17f3451c35c05f84b2c8227e6154956
MD5 66bcb5f90c8b7f4b0a1e1a27b05a584d
BLAKE2b-256 8c6ac84f44e7f60454aa026ac82bc6b2432753da1fd434a061c08651960c53f4

See more details on using hashes here.

File details

Details for the file secured_pip-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: secured_pip-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 34.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0b2

File hashes

Hashes for secured_pip-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a6b72f311a52758049b3827a24032abd0bddf86778e275030271f763c6c53f7a
MD5 882eb8bf2ccb25a1696ec447f6704154
BLAKE2b-256 0962fef531d10f0f252aebdc0674d034d207f6b292faa2b09ea243761fca0b78

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page