jupyter / jupyter/security

Audit all Jupyter PyPI package tokens

Open
#98 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Jupyter Notebook
Stars
27
Forks
12
Avg merge
3d 5h
Merged PRs (30d)
3

Description

Followup from https://github.com/jupyterhub/team-compass/issues/763#issuecomment-2751557550

Audit all PyPI packages under Jupyter to see:
- which ones are using a trusted publisher https://docs.pypi.org/trusted-publishers/using-a-publisher/
- which ones are using tokens, and when the token was last updated
- which ones are using trusted publisher but still have old tokens that should be deleted

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked team-compass follow-up and PyPI's trusted publishers documentation. Inventory Jupyter's PyPI packages, recording trusted-publisher use, token use, and token update dates; identify old tokens that should be deleted. Done when the full audit and deletion candidates are documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
jupyter-notebook, python
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.