skip_trace
Who owns your dependencies
- Can they be linked to a real person or company in the real world
- Can they be contacted
Of course all packages have a pypi user. The list of users isn't academic, you care about them because you want to communicate with them.
Installation
Requires
- Github key
- Initializing
spacygit clone,uv sync- OR
python -m spacy download en_core_web_sm - OR
python -c 'import spacy.cli; spacy.cli.download("en_core_web_sm")'
- (Not implemented yet) Openrouter/OpenAI key
Usage
skip-trace who-owns requests
What you will see is the owner table and the maintainer tables.
The owner table is pretty close to all the names, email addresses and custom domains I can find.
Use Cases
- You are worried about supply chain attacks and are concerned that a package is actually maintained by North Korean government backed hackers
- You need to file a bug report and there isn't an issue link
- You want to hire, buy something from the maintainer, or charitably donate money
- You want to do a PEP 541 take over
- You want to volunteer to take over an abandoned package instead of forking it
- You want to find out if your project is now unreachable. If you are conscientious enough to run this on your own packages, you probably are not the person to rigorously avoid adding contact information.
- You are trying to publish anonymously and want to check to see if the package is actually anonymous
Unreachable
See PEP 541 for exact text
- Do you have a real email address in your metadata
- Do you have a link to a page with your real email address or other means to reach you
Name Squatting
If a package has take a good name but the user has published nothing to it, that is Name Squatting
Prior Art
Nothing I could find.
Project Health & Info
| Metric | Health | Metric | Info |
|---|---|---|---|
| Tests | License | ||
| Coverage | PyPI | ||
| Lint / Pre-commit | Python Versions | ||
| Quality Gate | Docs | ||
| CI Build | Downloads | ||
| Maintainability | Last Commit |
| Category | Health |
|---|---|
| Open Issues | |
| Stars |
Metadata
Release files for skip-trace 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| skip_trace-0.1.1.tar.gz | 47.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| skip_trace-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 110.5 kB
Release files / skip_trace-0.1.1.tar.gz
| Download URL | skip_trace-0.1.1.tar.gz |
|---|---|
| Size | 47.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bb13af5afaf0168513248a12a53191ac04acd372b5ddc7b685c8b63b02d7a3fa
|
|
BLAKE2b-256 checksum How to use checksums |
bebccb2f68d3d05fac3a5b0a910e898d0ac8875a5481bb025d9b10e53b5da2c1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 12, 2025.
Transparency logRelease files / skip_trace-0.1.1-py3-none-any.whl
| Download URL | skip_trace-0.1.1-py3-none-any.whl |
|---|---|
| Size | 62.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2395dafc637d9ec0e0cd0cbf80abdc024696d23e4e8b70b432e600fb58e8370a
|
|
BLAKE2b-256 checksum How to use checksums |
d38761bf70a05062681fa85652f92d05e20039a531d42ea9cf73dfb6f256f67f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 12, 2025.
Transparency log