Skip to main content

skip_trace

Who owns your dependencies

  • Can they be linked to a real person or company in the real world
  • Can they be contacted

Of course all packages have a pypi user. The list of users isn't academic, you care about them because you want to communicate with them.

tests pre-commit.ci status Downloads Python Version Release

Installation

Requires

  • Github key
  • Initializing spacy
    • git clone, uv sync
    • OR python -m spacy download en_core_web_sm
    • OR python -c 'import spacy.cli; spacy.cli.download("en_core_web_sm")'
  • (Not implemented yet) Openrouter/OpenAI key

Usage

skip-trace who-owns requests

What you will see is the owner table and the maintainer tables.

The owner table is pretty close to all the names, email addresses and custom domains I can find.

Use Cases

  • You are worried about supply chain attacks and are concerned that a package is actually maintained by North Korean government backed hackers
  • You need to file a bug report and there isn't an issue link
  • You want to hire, buy something from the maintainer, or charitably donate money
  • You want to do a PEP 541 take over
  • You want to volunteer to take over an abandoned package instead of forking it
  • You want to find out if your project is now unreachable. If you are conscientious enough to run this on your own packages, you probably are not the person to rigorously avoid adding contact information.
  • You are trying to publish anonymously and want to check to see if the package is actually anonymous

Unreachable

See PEP 541 for exact text

  • Do you have a real email address in your metadata
  • Do you have a link to a page with your real email address or other means to reach you

Name Squatting

If a package has take a good name but the user has published nothing to it, that is Name Squatting

Prior Art

Nothing I could find.

Project Health & Info

Metric Health Metric Info
Tests Tests License License
Coverage Codecov PyPI PyPI
Lint / Pre-commit pre-commit.ci status Python Versions Python Version
Quality Gate Quality Gate Status Docs Docs
CI Build Build Downloads Downloads
Maintainability Maintainability Rating Last Commit Last Commit
Category Health
Open Issues GitHub issues
Stars GitHub Repo stars

Metadata

Release files for skip-trace 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for skip-trace 0.1.1
File Size Uploaded
skip_trace-0.1.1.tar.gz 47.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for skip-trace 0.1.1
File Interpreter ABI Platform
skip_trace-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 110.5 kB

Release files / skip_trace-0.1.1.tar.gz

Download URL skip_trace-0.1.1.tar.gz
Size 47.6 kB
Tags Source
SHA-256 checksum
How to use checksums
bb13af5afaf0168513248a12a53191ac04acd372b5ddc7b685c8b63b02d7a3fa
BLAKE2b-256 checksum
How to use checksums
bebccb2f68d3d05fac3a5b0a910e898d0ac8875a5481bb025d9b10e53b5da2c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 12, 2025.

Transparency log

Release files / skip_trace-0.1.1-py3-none-any.whl

Download URL skip_trace-0.1.1-py3-none-any.whl
Size 62.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2395dafc637d9ec0e0cd0cbf80abdc024696d23e4e8b70b432e600fb58e8370a
BLAKE2b-256 checksum
How to use checksums
d38761bf70a05062681fa85652f92d05e20039a531d42ea9cf73dfb6f256f67f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 12, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page