Python Package Index Key
Description
General
- Documentation: https://warehouse.readthedocs.io/api-reference/index.html
- Summary: The python package index also called PyPI is the official software repository for Python. It is often used as a default source for packages by package managers. PyPI exposes an API to interact with the repository. This detectors catches the PyPI API keys used to perform authentication when uploading packages.
Revoke the secret
API keys can be revoked from the account settings page.
Details for Python Package Index Key
-
Family: token
-
Category: package_registry
-
Company: Python Package Index
-
High recall: True
-
Validity check available: True
-
Analyzer available: True
-
Revoker available: False
-
On-premise instances exist: False
-
Only valid secrets raise an alert: False
-
Occurrences found for one million commits: 4.47
-
Prefixed: True
Secret Analyzer
Analysis Method
- Provider allows scopes enumeration: True
- Total network call count: 2
- Total call count may vary: True
HTTP Calls
Requests are designed to capture metadata and not to function effectively.
- POST:
https://test.pypi.org/legacy/ - POST:
https://upload.pypi.org/legacy/
Other Calls
Non-HTTP queries or HTTP calls made through a third-party app (e.g., Python package). No other calls for this analyzer.