Skip to main content

A defensive pip wrapper with supply-chain preflight checks.

Project description

Not Finished Yet. Contribution Welcome. Site at https://spip.lamentxu.top/

secured_pip

Test License: MIT Python_version PyPI Version Codecov

An open-source, free guard for your pip to avoid supply-chain attacks.

By using this, you can avoid being screwed by the poisoned LiteLLM, etc. just because you type pip install

What?

Currently, supply chain attacks are one of the major security concerns all over the world. The secured_pip project is a future pip wrapper focused on supply-chain risk controls.

Wait, What?

You can use

spip install requests

Instead of

pip install requests

To install a package more safely in the scope of supply chain security.

You do not need to configure. You do not need to learn. Just pure install-to-master.

In other words, you can completely replace pip install with spip install to make your installation safer :)

If you want a near drop-in experience, you can set a shell alias from pip to spip.

Command Prompt (Windows):

doskey pip=spip $*

Bash (Linux):

echo "alias pip='spip'" >> ~/.bashrc
source ~/.bashrc

Zsh (macOS):

echo "alias pip='spip'" >> ~/.zshrc
source ~/.zshrc

The secured_pip project will actively check for all the supply chain risks and avoid you installing potentially malicious packages when typing spip install

For install, spip uses pip's own resolver and then checks the selected install plan before pip builds or installs the resolved distributions. If the checks pass, the same pip install flow continues; spip does not run a second pip install for the already-resolved packages.

Except for the install commands, the project behaves exactly the same as the original pip program. That is, you can always use spip instead of pip in any case :)

If you want to refresh local caches used by spip, run:

spip refresh-cache

Why not SFW / GuardDog?

There are already good supply-chain tools out there. secured_pip is not trying to replace all of them. The point is different: keep the protection path as light as possible for everyday Python installs.

  • Compared with Socket Firewall (sfw): Socket Firewall works as a wrapper/proxy layer in front of package-manager network requests and uses Socket's security intelligence to block packages before download. secured_pip is much smaller in scope: it is a local Python-only pip wrapper, with no proxy service, no organization dashboard, and no extra infrastructure to run. Official Socket docs: https://docs.socket.dev/docs/socket-firewall-overview
  • Compared with GuardDog: GuardDog is a scanning CLI that downloads package source archives and applies source-code and metadata heuristics, including Semgrep-based rules. secured_pip is intentionally lighter: it stays close to pip install, does quick local checks around the install flow, and does not try to be a full package-code scanner. Official GuardDog README: https://github.com/DataDog/guarddog

In short, secured_pip optimizes for:

  • near-drop-in use with spip install
  • local, lightweight checks
  • minimal workflow change
  • Python / pip focus instead of broad multi-ecosystem coverage

Current minimum Python version: 3.10

We currently have three install warning policies:

  • HIGH: pause installation and require --ignore-warning
  • MEDIUM: prompt y/n before continuing
  • LOW: warn and continue

The default sensitivity is low, which uses the policy above. You can make the gate stricter with --sensitivity medium or --sensitivity high:

  • --sensitivity medium: MEDIUM and above pause installation; LOW prompts.
  • --sensitivity high: LOW and above pause installation.

When spip detects a potential risk, a warning will be raised, with the level depending on the severity the risk is.

For now, the project has several major check points:

  • Fake typo checks: Hackers often use "fake typos" to inject a malicious dependency package into the poisoned source file. spip detects this by first resolving all the packages that pip install is going to download, and then comparing non-popular resolved package names with a local hot-package list. Warning levels:
    • Medium severity: requsets vs requests
    • Medium severity: pandaz vs pandas
    • Low severity: sixth vs six
  • Direct URL dependency checks: If the install target or a resolved dependency uses a direct URL, VCS URL, or PEP 508 direct reference, spip will raise a MEDIUM warning.
  • Fresh release checks: If the selected PyPI release was published less than 2 days ago, spip will raise a MEDIUM warning.
  • Disposable email checks: If the PyPI release metadata uses a known disposable author or maintainer email domain, spip will raise a LOW warning. The built-in blocklist is vendored from disposable/disposable-email-domains strict mode.
  • Empty description checks: If the selected PyPI release metadata has no summary and no long description, spip will raise a LOW warning.
  • Suspicious metadata URL checks: If PyPI metadata points to a shortener, raw IP, suspicious TLD, embedded credentials, or similar suspicious URL, spip will raise a LOW warning.
  • Repository mismatch checks: If PyPI metadata points to a GitHub/GitLab repository whose repo name appears unrelated to the package name, spip will raise a LOW warning.
  • Maintainer email domain drift checks: If a package's maintainer email domain changes compared with the local spip history cache, spip will raise a LOW warning.
  • Zero-version checks: If the selected package version is 0.0 or 0.0.0, spip will raise a LOW warning.
  • .pth file detection: Instead of directly injecting malicious code inside the package, today most hackers will place their bad stuff under a .pth file, with an import as the beginning. spip only checks the installed file-system diff after installation. The warning level is always MEDIUM, and spip will ask whether to delete the suspicious installed .pth file.
  • TODO ...

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

secured_pip-0.4.2.tar.gz (466.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

secured_pip-0.4.2-py3-none-any.whl (450.1 kB view details)

Uploaded Python 3

File details

Details for the file secured_pip-0.4.2.tar.gz.

File metadata

  • Download URL: secured_pip-0.4.2.tar.gz
  • Upload date:
  • Size: 466.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0b2

File hashes

Hashes for secured_pip-0.4.2.tar.gz
Algorithm Hash digest
SHA256 9bd101335602c0772cf9f6cdedf511ecb8f2f15b3fd0fea735f06f7e3722b40e
MD5 d5b1059e8962a211bbc0c9d78ded738f
BLAKE2b-256 ac581ae7986a9ee7b3e85e9cbfde13e8dd012ee2ba5a41fe32a58ee00abe0edc

See more details on using hashes here.

File details

Details for the file secured_pip-0.4.2-py3-none-any.whl.

File metadata

  • Download URL: secured_pip-0.4.2-py3-none-any.whl
  • Upload date:
  • Size: 450.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0b2

File hashes

Hashes for secured_pip-0.4.2-py3-none-any.whl
Algorithm Hash digest
SHA256 65df75bbf3b37474e7459d88eb2f03372cac859b0ed8b5b551dd2b8c15d1121d
MD5 3594b3009151fc839a2854e2d88e52b8
BLAKE2b-256 f67168bccf87a184d9bf8eaceca0035f4520898938814ecfc306af0b4b61d7db

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page