Skip to main content

FULL HTML Documentation: http://jamercee.github.io/signet/

Signet provides support for building and delivering tamper resistant python to your users and customers.

Signet creates a custom python loader which you deliver with your script. On each invocation, the loader will verify no tampering has ocurred before it runs the python script.

Users have the confidence of knowing their scripts are safe and yet retain full access to the python source for code review and enhancement. And you know your users are running the right version of code.

Signet is fully integrated with distutils to make the process of building and installing new python projects as simple and painless as possible.

How does it work?

Signet relies on the strength of cryptographic hash to reliably detect file modifications. Signet builds hashes of your script and all it’s dependencies. These hashes are incorporated into a custom python loader which will handle re-verifying the hashes before it will run your script.

If your script or any of it’s dependencies are tampered with, the loader will emit an error and exit. If everything matches, the loader will run your script.

Example usage

For example, if you had a simple script hello.py:

import os
print('hello from %s' % os.name)

And you deployed it with this simple setup.py:

from distutils.core import setup, Extension
from signet.command.build_signet import build_signet

setup(name = 'hello',
    cmdclass = {'build_signet': build_signet, },
    ext_modules = [Extension('hello', sources=['hello.py'])],
    )

Build your loader:

python setup.py build_signet

On Windows you’ll have hello.exe and on Linux you’ll have hello.

The signet system also provides facilities for code signing:

from distutils.core import setup, Extension
from signet.command.build_signet import build_signet, sign_code

setup(name = 'hello',
    cmdclass = {'build_signet': build_signet,
                'sign_code': sign_code,
               },
    ext_modules = [Extension('hello', sources=['hello.py'])],
    )

Build your loader:

python setup.py build_signet
python setup.py sign_code --savedpassword --pfx-file {path-to-pfx}

Installing Signet

Signet is hosted on github at https://github.com/jamercee/signet

Installation using git:

git clone https://github.com/jamercee/signet
cd signet
python setup.py install

Signet can also be installed with pip:

pip install signet

Features

  • Multiplatform: works under

    • Windows (32/64-bit)

    • Linux

    • FreeBSD

  • Integrated with Distutils

  • Protection from tampering (SHA1 hashed content)

  • On Windows

    • Provides code signing executables

    • PE executable verification

    • Automatic resource file generation

    • Customizable program icon

  • Customizable python loader (full c++ included)

  • Unique process name

    • show hello rather than python hello.py

  • Compatible with virtualenv

Metadata

Release files for signet 3.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for signet 3.0.2
File Size Uploaded
signet-3.0.2.tar.gz 32.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for signet 3.0.2
File Interpreter ABI Platform
signet-3.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 61.4 kB

Release files / signet-3.0.2.tar.gz

Download URL signet-3.0.2.tar.gz
Size 32.0 kB
Tags Source
SHA-256 checksum
How to use checksums
62bb307911f33d701367fcede96b0b6730a628c33491854c141ff071587b1011
BLAKE2b-256 checksum
How to use checksums
5d158b59fe6db7b6ace00b222552f0cf10806dc1ccfa7ddddd81897f78154235
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/45.1.0 requests-toolbelt/0.9.1 tqdm/4.46.1 CPython/3.8.1

Release files / signet-3.0.2-py3-none-any.whl

Download URL signet-3.0.2-py3-none-any.whl
Size 29.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b0c0f6d46a6ee83cea25d6f021c5058f9ebae7062dcdd0d418c3c30a7c23b47f
BLAKE2b-256 checksum
How to use checksums
0e9177f71959262a8fe9aa59c61f15be50bc162b78079b3f0c17fef4c5e4b98a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.1.1 pkginfo/1.5.0.1 requests/2.22.0 setuptools/45.1.0 requests-toolbelt/0.9.1 tqdm/4.46.1 CPython/3.8.1

Release history Release notifications | RSS feed

This release

3.0.2 This release

2 release files

3.0.1

3 release files

1.0.20

1 release file

1.0.18

1 release file

1.0.17

1 release file

1.0.16

1 release file

1.0.15

1 release file

1.0.14

1 release file

1.0.12

1 release file

1.0.11

1 release file

1.0.10

1 release file

1.0.9

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page