No project description provided
Project description
Twyn
Twyn is a security tool that compares the name of your dependencies against a set of the most popular ones, in order to determine if there is any similarity between them, preventing you from using a potentially illegitimate one. In short, Twyn protects you against typosquatting attacks.
It works as follows:
- Either choose to scan the dependencies in a dependencies file you specify (
--dependency-file
) or some dependencies introduced through the CLI (--dependency
). If no option was provided, it will try to find a dependencies file in your working path. - If the name of your package name matches with the name of one of the most well known packages, the package is accepted.
- If the name of your package is similar to the name of one of the most used packages, Twyn will prompt an error.
- If your package name is not in the list of the most known ones and is not similar enough to any of those to be considered misspelled, the package is accepted. Twyn assumes that you're using either a not so popular package (therefore it can't verify its legitimacy) or a package created by yourself, therefore unknown for the rest.
Docker
Twyn provides a Docker image, which can be found here.
Quickstart
Installation
Twyn is available on PyPi repository, you can install it by running
pip install twyn
Run
To run twyn simply type:
twyn run <OPTIONS>
For a list of all the available options as well as their expected arguments run:
twyn run --help
Configuration
Allowlist
It can happen that a legitimate package known by the user raises an error because is too similar to one of the most trusted ones.
You can then add this packages to the allowlist
, so it will be skipped:
twyn allowlist add <package>
To remove it simply:
twyn allowlist remove <package>
Dependency files
To specify a dependency file through the command line run:
twyn run --dependency-file <file path>
Currently it supports these dependency file formats.
requirements.txt
poetry.lock
Check dependencies introduced through the CLI
You can also check a dependency by entering it through the command line:
twyn run --dependency <dependency>
It does accept multiple dependencies at a time:
twyn run --dependency <dependency> --dependency <another_dependency>
When this option is selected, no dependency file is checked.
Selector method
You can choose between different operational modes:
all
: Default option. It is the most exhaustive mode. It will check your package names against the trusted ones without any assumption.nearby-letter
: will consider a possible typo in the first letter of your package name, so it will also consider all the nearby characters (in an English keyboard) when computing the distance between words.first-letter
: will assume the first letter of your package is correct. It is the fastest mode but the least reliable one.
To select a specific operational mode through the CLI use the following command
twyn run --selector-method <method>
Configuration file
You can save your configurations in a .toml
file, so you don't need to specify them everytime you run Twyn in your terminal.
By default, it will try to find a pyproject.toml
file in your working directory when it's trying to load your configurations.
However, you can specify a config file as follows:
twyn run --config <file>
All the configurations available through the command line are also supported in the config file.
[tool.twyn]
dependency_file="/my/path/requirements.txt"
selector_method="first_letter"
logging_level="debug"
allowlist=["my_package"]
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file twyn-2.7.4.tar.gz
.
File metadata
- Download URL: twyn-2.7.4.tar.gz
- Upload date:
- Size: 15.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.4 CPython/3.10.2 Linux/6.5.0-1025-azure
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 49b8d12b96638c190847628922d1f2f3c4e15855301937b9274ebd6e5d7b3f03 |
|
MD5 | dbee8d5e0c73112ee47c99192171bc30 |
|
BLAKE2b-256 | b13988b66db1c811b2fc7893b7a6e7210c33bd368f8711c7f5407cbc84204482 |
File details
Details for the file twyn-2.7.4-py3-none-any.whl
.
File metadata
- Download URL: twyn-2.7.4-py3-none-any.whl
- Upload date:
- Size: 19.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.4 CPython/3.10.2 Linux/6.5.0-1025-azure
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 63a7ce89ee91df1f5f8d7cacf6c831dd0e26bb5616d4d2fde36d0b3092920239 |
|
MD5 | b9b0a8021e1802a015047b229c18e787 |
|
BLAKE2b-256 | a0ed8553227f1168896752f493847b8b15096baf19a0c735aaa309dc676564ba |