Skip to main content

TrustSource plugin for scanning python project installed pip dependencies and uploading them to [TrustSource](https://app.trustsource.io) via its API for code compliance evaluation

Project description

TrustSource-pip-scan

TrustSource plugin for scanning python project install pip dependencies and uploading them https://app.trustsource.io for code compliance evaluation This package came about because official TrustSource provided packages (ts-pip-plugin, ts-python-client) and either don't work as of this time or don't provide good integration in the CI/CD pipelines for python projects. The library is influenced by ts-pip-plugin

This plugin is geared towards the use in CI/CD pipelines. It can do legal and vulnerability evaluation after TrustSource analysed the scan results. The package command exist with code 1 if evaluation fails.

Installation

Installation from pip

    pip install ts-pip-scan

Installing it from local dir

git clone https://github.com/JoeMabor/TrustSource-pip-scan.git

pip install <path>/TrustSource-pip-scan

Usage

TrustSource project and api key can be provided as options in the commandline or ts-plugin.json that can be added to root dir of the project to be scanned. Content of ts-plugin.json

{
    "project": "<TrustSource Project Name>",
    "apiKey": "<api-key>",
    base_url: str = TS_API_URL
    max_legal_warnings: 0
    max_legal_violations: 0
    max_vulnerability_warning: 0
    max_vulnerability_violations: 0
    skip_upload: false
    
}

Scan dependencies and upload them to TrustSource

ts-pip-scan scan <path-to-project-being-scanned/

Scan dependencies, upload to TrustSource and evaluate legal and vulnerability analysis

ts-pip-scan scan -val <path-to-project-being-scanned/

Scan dependencies without uploading results

ts-pip-scan scan --skip-upload <path-to-project-being-scanned/

For info about options, run

ts-pip-scan --help
ts-pip-scan scan --help

Some configs can be set as environment variables

max_legal_warnings -> TS_MAX_LEGAL_WARNINGS
max_legal_violations -> TS_MAX_LEGAL_VIOLATIONS
max_vulnerability_warnings -> TS_MAX_VULNERABILITY_WARNINGS
max_vulnerability_violations -> TS_MAX_VULNERABILITY_VIOLATIONS
TS_SKIP_UPLOAD -> skip_upload

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ts_pip_scan-1.0.1.tar.gz (10.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ts_pip_scan-1.0.1-py3-none-any.whl (11.2 kB view details)

Uploaded Python 3

File details

Details for the file ts_pip_scan-1.0.1.tar.gz.

File metadata

  • Download URL: ts_pip_scan-1.0.1.tar.gz
  • Upload date:
  • Size: 10.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.9.16

File hashes

Hashes for ts_pip_scan-1.0.1.tar.gz
Algorithm Hash digest
SHA256 10f9b78a6556e21c26d45aaa4ccf80973c0988d493ff470fa89b4fc91ed78a23
MD5 23684fbbfdd5d69ca9b778c44ba9905b
BLAKE2b-256 50923a3de3da8ec16ce5b3b96448c022cd8732f60540493f1e287972274dffd8

See more details on using hashes here.

File details

Details for the file ts_pip_scan-1.0.1-py3-none-any.whl.

File metadata

  • Download URL: ts_pip_scan-1.0.1-py3-none-any.whl
  • Upload date:
  • Size: 11.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.9.16

File hashes

Hashes for ts_pip_scan-1.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 725e561350eee47613c487d2eb0b8d3924aa05e04429d017045e71f3b13d98e3
MD5 88e4fa50c41dc7528c8dbfb474857b7f
BLAKE2b-256 7665a2cb6348f4d52a2cb8c7ef1c84219e41b6b8aa5f47cea54ee1793f60728b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page