Python Dependency Security¶
Source: hooks/ways/softwaredev/code/supplychain/depscan/python/python.md
Frontmatter
| Field | Value |
|---|---|
description |
Python dependency security, pip-audit, setup.py risks, PyPI typosquatting |
vocabulary |
pip-audit setup.py pyproject.toml requirements.txt wheel sdist PyPI typosquat safety pip install python package |
refire |
0.15 |
scope |
agent, subagent |
Scanning¶
# Preferred: scan without installing
pip-audit -r requirements.txt
osv-scanner --lockfile=requirements.txt
# If already installed
pip-audit
Python-Specific Risks¶
setup.pyruns on install.pip install .executessetup.py— any code in there runs with your permissions. Read it first for unfamiliar packages.pyproject.tomlis safer but can still specify build backends that execute code.- Pickle files are code.
pickle.load()can execute arbitrary Python. Never unpickle data from untrusted sources. Same formarshal,shelve,yaml.load()(useyaml.safe_load()). - Typosquatting on PyPI is real.
reqeustsinstead ofrequests. Check package names carefully, especially in copied requirements files.