# python packages

Published articles for python packages.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Why Backporting Python Security Fixes Is Complex and Risky

DevFeed: [Why Backporting Python Security Fixes Is Complex and Risky](<https://devfeed.tech/articles/this-shit-is-hard-the-complexities-of-fixing-python-library-security-issues-at-scale-13290.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-the-complexities-of-fixing-python-library-security-issues-at-scale>)

Published: 2026-02-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>)

Tags: [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [python](<https://devfeed.tech/tags/python.md>), [python-dependencies](<https://devfeed.tech/tags/python-dependencies.md>), [python-libraries](<https://devfeed.tech/tags/python-libraries.md>), [python-packages](<https://devfeed.tech/tags/python-packages.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-python-libraries](<https://devfeed.tech/tags/zero-cve-python-libraries.md>)

### AI overview

The article explains why updating vulnerable Python dependencies can be difficult when compatibility constraints prevent immediate upgrades. It argues that manually backporting security patches is complex, time-consuming, and risky, and presents Chainguard Libraries as a source of tested and verified patched packages.

### Source excerpt

Backporting Python CVE fixes is complex and risky. Chainguard Libraries delivers source-built, tested, and verified patched packages you can trust.

## Introducing automatic, short-lived credentials for Chainguard Libraries for Python

DevFeed: [Introducing automatic, short-lived credentials for Chainguard Libraries for Python](<https://devfeed.tech/articles/introducing-automatic-short-lived-credentials-for-chainguard-libraries-for-python-13105.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-automatic-short-lived-credentials-for-chainguard-libraries-for-python>)

Published: 2026-01-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [pip](<https://devfeed.tech/topics/pip.md>), [developer velocity](<https://devfeed.tech/topics/developer-velocity.md>), [Usability](<https://devfeed.tech/topics/usability.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-libraries-python](<https://devfeed.tech/tags/chainguard-libraries-python.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [chainguard-python-containers](<https://devfeed.tech/tags/chainguard-python-containers.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python-libraries](<https://devfeed.tech/tags/python-libraries.md>), [python-packages](<https://devfeed.tech/tags/python-packages.md>), [secure-python-packages](<https://devfeed.tech/tags/secure-python-packages.md>), [security](<https://devfeed.tech/tags/security.md>), [usability](<https://devfeed.tech/tags/usability.md>)

### AI overview

Chainguard announces integrated authentication for Chainguard Libraries for Python through a keyring package. The package provides short-lived credentials that refresh automatically, enabling secure pip access without repeatedly creating, copying, or managing long-lived tokens. It supports local development and GitHub Actions environments with assumable identities.

### Source excerpt

New integrated authentication for Python Libraries with a keyring: use short-lived credentials for pip installs to stay secure without slowing developers down.

## The ultimate guide to creating a secure Python package

DevFeed: [The ultimate guide to creating a secure Python package](<https://devfeed.tech/articles/the-ultimate-guide-to-creating-a-secure-python-package-8221.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ultimate-guide-creating-secure-python-package/>)

Author: Gourav Singh Bais

Published: 2024-05-08T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [pip](<https://devfeed.tech/topics/pip.md>), [Code](<https://devfeed.tech/topics/code.md>), [Security](<https://devfeed.tech/topics/security.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [draftdotdev](<https://devfeed.tech/tags/draftdotdev.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [github](<https://devfeed.tech/tags/github.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [installation](<https://devfeed.tech/tags/installation.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [packages](<https://devfeed.tech/tags/packages.md>), [pycharm](<https://devfeed.tech/tags/pycharm.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [python-packages](<https://devfeed.tech/tags/python-packages.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This guide explains how to create a modern secure Python package, covering package structure, metadata, tests, documentation, installation, imports, distribution, and use of public or private package indexes. It also discusses using TLS to secure private indexes and provides a GitHub repository with the tutorial code.

### Source excerpt

This guide will detail all the steps to build a modern Python package.

## Getting Started with Pipenv

DevFeed: [Getting Started with Pipenv](<https://devfeed.tech/articles/getting-started-with-pipenv-26288.md>)

Original publisher: [Read original article](<https://masnun.com/pipenv-getting-started/>)

Author: masnun

Published: 2017-11-25T23:09:32Z

Content type: tutorial

Language: en

Sources: [Abu Ashraf Masnun](<https://devfeed.tech/sources/abu-ashraf-masnun.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [pip](<https://devfeed.tech/topics/pip.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [PyPI](<https://devfeed.tech/topics/pypi.md>), [Flask](<https://devfeed.tech/topics/flask.md>), [PyCharm](<https://devfeed.tech/topics/pycharm.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [dependencies](<https://devfeed.tech/tags/dependencies.md>), [environment-management](<https://devfeed.tech/tags/environment-management.md>), [getting-started](<https://devfeed.tech/tags/getting-started.md>), [install](<https://devfeed.tech/tags/install.md>), [packaging](<https://devfeed.tech/tags/packaging.md>), [pycharm](<https://devfeed.tech/tags/pycharm.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [python-packages](<https://devfeed.tech/tags/python-packages.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A tutorial introducing Pipenv for Python development. It explains how Pipenv combines package installation with isolated virtual environments, records dependencies in a Pipfile, creates a lock file for deterministic builds, and supports installing packages, running applications, activating environments, and managing dependencies.

### Source excerpt

If you're a Python developer, you probably know about pip and the different environment management solutions like virtualenv or venv. The pip tool is currently the standard way to install a Python package. Virtualenv has been a popular way of isolating Python environments for a long time. Pipenv combines the very best of these tools [...] The post Getting Started with Pipenv appeared first on Abu Ashraf Masnun.

## Installing Python Packages

DevFeed: [Installing Python Packages](<https://devfeed.tech/articles/installing-python-packages-41102.md>)

Original publisher: [Read original article](<https://www.craigkerstiens.com/2011/11/01/Installing-Python-Packages/>)

Author: Map

Published: 2011-11-01T20:55:56Z

Content type: tutorial

Language: en

Sources: [Craig Kerstiens](<https://devfeed.tech/sources/craig-kerstiens.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [pip](<https://devfeed.tech/topics/pip.md>), [PyPI](<https://devfeed.tech/topics/pypi.md>), [Django](<https://devfeed.tech/topics/django.md>)

Tags: [install](<https://devfeed.tech/tags/install.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [python-packages](<https://devfeed.tech/tags/python-packages.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

A tutorial on installing Python packages with pip, using a virtualenv environment, and recording installed package versions for sharing through a requirements list. It explains that packages are hosted on PyPI and demonstrates creating, activating, and deactivating an isolated project environment.

### Source excerpt

Now that you have you system and project environment all setup you probably want to start developing. But you likely don't want to start writing an entire project fully from scratch, as you dive in you'll quickly realize theres many tools helping you build projects and sites faster. For example making a request to a website there's Requests, for handling processing images there's Python Imaging Library, or for a full framework to help you in building a site there's Django. With all of these there's one simple and common way to install them. But first a little more on how it all works. All major Python packages are hosted on PyPi (Pronounced Pi-P or Cheeseshop). When you use a common python installer it will: Search for the package you specify If you specify a version will use it, otherwise will use the latest Will download the source for that package Install it into your Python environment Now for actually installing... Lets get started with installing the three packages below. At this point you should at least have a fresh Python environment, however you don't have an immediate way to install packages. The defacto Python package installer is pip. Earlier we setup virtualenv to help isolate our python packages we were working with. First lets go ahead and create a folder for our project then setup a new environment for the project we'll work on: $ mkdir myapp $ cd myapp $ virtualenv --no-site-packages venv If we list the contents of the directory you'll now see a folder venv. Within this folder you'll find all the parts of the environment that virtualenv just created: $ ls venv $ ls venv bin include lib Now you've got a sandboxed environment that exists but you haven't loaded it. You can now activate and deactivate this any time you like. Once you do this it customizes your path to use the packages you've installed for this environment. To load your environment when in the myapp directory: $ source venv/bin/activate To deactivate this simple: $ deactivate Now that we'