wheel-crypto-scan
Reports crypto-relevant evidence found inside Python wheels: which primitive families and libraries are present, how they are linked, what the Python code does with TLS, hashing and randomness, and whether post-quantum algorithms show up. That is the account a package index's consumers get, wheel by wheel.
FIPS compatibility is one lens over that account, not its whole purpose: whether a FIPS-enforcing host can run the wheel's crypto as shipped, so consuming teams can gauge FIPS risk before they ship it. It gathers evidence. It does not decide FIPS compliance.
Install and run
uv tool install . # or: uv run wheel-crypto-scan
wheel-crypto-scan scan /path/to/wheels -o index.jsonl --jobs 8
Full docs — the FIPS lens, every flag, the output schema, the ruleset, and the design calls that cost something: https://my1.fr/wheel-crypto-scan/
Development
uvx --with tox-uv tox # tests across py311-py314, plus ruff lint and format
uvx --with tox-uv tox -e lint
See Contributing for adding policy, changing extraction, writing up a design call, and releasing.
Licence
Apache 2.0. See LICENSE.
Release files for wheel-crypto-scan 0.1.8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| wheel_crypto_scan-0.1.8.tar.gz | 843.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| wheel_crypto_scan-0.1.8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.1 MB
Release files / wheel_crypto_scan-0.1.8.tar.gz
| Download URL | wheel_crypto_scan-0.1.8.tar.gz |
|---|---|
| Size | 843.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fffa0af4ecf176a08270cae02a17692d99cb6332c8d9f97644c5a04ecc82b9c3
|
|
BLAKE2b-256 checksum How to use checksums |
6b6fbe1c1ca8ca61f40c93d07b4733a229c755667f49d1c3e90d0880c81d6d38
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / wheel_crypto_scan-0.1.8-py3-none-any.whl
| Download URL | wheel_crypto_scan-0.1.8-py3-none-any.whl |
|---|---|
| Size | 293.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9006ede6e943dee89124acb38cd1f1a733fe3bf40ed44eb2d178c7f80a7f06a3
|
|
BLAKE2b-256 checksum How to use checksums |
ae3683b12a06f63703b3c82b715c2e774350103a0ad3153f88b75bd69a168ff3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency log