TrustSource plugin for scanning python project installed pip dependencies and uploading them to [TrustSource](https://app.trustsource.io) via its API for code compliance evaluation
Project description
TrustSource-pip-scan
TrustSource plugin for scanning python project install pip dependencies and uploading them https://app.trustsource.io for code compliance evaluation This package came about because official TrustSource provided packages (ts-pip-plugin, ts-python-client) and either don't work as of this time or don't provide good integration in the CI/CD pipelines for python projects. The library is influenced by ts-pip-plugin
This plugin is geared towards the use in CI/CD pipelines. It can do legal and vulnerability evaluation after TrustSource analysed the scan results. The package command exist with code 1 if evaluation fails.
Installation
Installation from pip
pip install ts-pip-scan
Installing it from local dir
git clone https://github.com/JoeMabor/TrustSource-pip-scan.git
pip install <path>/TrustSource-pip-scan
Usage
TrustSource project and api key can be provided as options in the commandline or ts-plugin.json that can be added to root dir of the project to be scanned. Content of ts-plugin.json
{
"project": "<TrustSource Project Name>",
"apiKey": "<api-key>",
base_url: str = TS_API_URL
max_legal_warnings: 0
max_legal_violations: 0
max_vulnerability_warning: 0
max_vulnerability_violations: 0
skip_upload: false
}
Scan dependencies and upload them to TrustSource
ts-pip-scan scan <path-to-project-being-scanned/
Scan dependencies, upload to TrustSource and evaluate legal and vulnerability analysis
ts-pip-scan scan -val <path-to-project-being-scanned/
Scan dependencies without uploading results
ts-pip-scan scan --skip-upload <path-to-project-being-scanned/
For info about options, run
ts-pip-scan --help
ts-pip-scan scan --help
Some configs can be set as environment variables
max_legal_warnings -> TS_MAX_LEGAL_WARNINGS
max_legal_violations -> TS_MAX_LEGAL_VIOLATIONS
max_vulnerability_warnings -> TS_MAX_VULNERABILITY_WARNINGS
max_vulnerability_violations -> TS_MAX_VULNERABILITY_VIOLATIONS
TS_SKIP_UPLOAD -> skip_upload
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ts_pip_scan-1.0.2.tar.gz.
File metadata
- Download URL: ts_pip_scan-1.0.2.tar.gz
- Upload date:
- Size: 10.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.9.16
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f1d186305aa640e2404627c81f6a7f320d424f30f7532b8e3684e47d88f4d929
|
|
| MD5 |
3c6852bc3d209ebb054802899ace1984
|
|
| BLAKE2b-256 |
f95d77f9b42b8d07bfbb53266f3217c6eb1e62c98fefdf45275943fdbd7e6235
|
File details
Details for the file ts_pip_scan-1.0.2-py3-none-any.whl.
File metadata
- Download URL: ts_pip_scan-1.0.2-py3-none-any.whl
- Upload date:
- Size: 11.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.9.16
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a3b51f4b46b5801bf044dcd84317a8c1b790204d804f108d7a49bc3afeff9868
|
|
| MD5 |
e102b13effa81f58fe926d372b2cfa17
|
|
| BLAKE2b-256 |
df3d83e033436d42991cf0bb8ce57827f2d3df5baf77d25bad15305240d1ed2e
|