pipebreach/phantom scan

Detect divergence between a package's declared source and its published artifact

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
specPackage spec to scan, e.g. requests==2.31.0yes
ecosystemPackage ecosystemnopypi
sarif-filePath where the SARIF report is written (removed on execution error)nophantom-results.sarif
fail-on-out-of-scopeFail when the release has no pure-Python wheel (phantom exit 3)nofalse
namedescription
exit-codephantom exit code (0 clean, 1 findings, 2 error, 3 out of scope)
sarif-filePath of the written SARIF report