guarddog
pypi-command-line
guarddog | pypi-command-line | |
---|---|---|
6 | 3 | |
491 | 43 | |
2.9% | - | |
9.1 | 3.7 | |
4 days ago | 7 months ago | |
Python | Python | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
guarddog
-
'everything' blocks devs from removing their own NPM packages
Yes. https://securitylabs.datadoghq.com/articles/guarddog-identif....
-
A Tale of Two Kitchens - Hypermodernizing Your Python Code Base
GuardDog is a CLI tool that allows to identify malicious PyPI packages.
-
PyPI new user and new project registrations temporarily suspended
I've been very cautious the last couple of years due to these bad actors when looking at packages that might suit my needs. If there is no online presence of the source code (git anything, zips/gzs, etc), multiple packages submitted in a short time frame, or a greater than normal amount, an/or a derivation/plugin of a popular package it's usually a no-go.
For those that I do possibly trust, I then download the package (pip download) and review it. Doing a quick regex for URLs or exec() calls helps, but I probably should use something like guarddog (https://github.com/DataDog/guarddog)
-
451 PyPI packages install Chrome extensions to steal crypto
I woul not use a freeVPN service, honestly. Anyway, you could try to check the code or help with some stuff like this: https://securitylabs.datadoghq.com/articles/guarddog-identify-malicious-pypi-packages/ .
- Finding malicious PyPI packages through static code analysis: Meet GuardDog
- Identify malicious PyPI packages using static analysis and metadata heuristics
pypi-command-line
- pypi-command-line: A beautiful command line interface for pypi.org
-
Viewing python packages' information directly from the terminal
The source code is available on GitHub: wasi-master/pypi-command-line
-
I made a command-line-interface for PyPI as a 14 year old
Documentation: https://wasi-master.github.io/pypi-command-line/ GitHub: https://github.com/wasi-master/pypi-command-line PyPI: https://pypi.org/project/pypi-command-line
What are some alternatives?
AudioBook - Listen to Pdf/Rtf/txt/docs/epub/mobi/odt book with just a few line of Python code. Leave a :star: if you like It.
lookatme - An interactive, terminal-based markdown presenter
zeplyn - zeplyn makes package publishing quick and easy so you can reiterate faster
termplotlib - :chart_with_upwards_trend: Plotting on the command line
TheAlgorithms - All Algorithms implemented in Python
spotify-cli - Control Spotify playback on any device through the command line.
starcli - :sparkles: Browse trending GitHub projects from your command line
markdown-toc-extract - Extract a table of contents from a markdown file (CLI tool)
malicious-software-packages-dataset - An open-source dataset of malicious software packages found in the wild, 100% vetted by humans.
rosbag-compare - PyPi package for comparing ROS topics contained in a group of rosbags
art - 🎨 ASCII art library for Python
GoogleNews - Script for GoogleNews