Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Flake9 is a fork of Flake8 that supports reading configuration from a
pyproject.toml
file, because the authors of Flake8 won't implement it.
In addition, because it's 2020, Python 2.7 support has been dropped.
Here's an example of the pyproject.toml
file::
[tool.flake8]
ignore = "E203,E266,H106,H904"
max-line-length = 88
max-complexity = 25
hang-closing = true
Flake8 is a wrapper around these tools:
Flake8 runs all the tools by launching the single flake8
command.
It displays the warnings in a per-file, merged output.
It also adds a few features:
files that contain this line are skipped::
lines that contain a # noqa
comment at the end will not issue warnings.
you can ignore specific errors on a line with # noqa: <error>
, e.g.,
# noqa: E234
. Multiple codes can be given, separated by comma. The noqa
token is case insensitive, the colon before the list of codes is required otherwise the part after noqa
is ignored
Git and Mercurial hooks
extendable through flake8.extension
and flake8.formatting
entry
points
See our quickstart documentation <http://flake8.pycqa.org/en/latest/index.html#quickstart>
_ for how to install
and get started with Flake8.
Flake8 maintains an FAQ <http://flake8.pycqa.org/en/latest/faq.html>
_ in its
documentation.
If you have questions you'd like to ask the developers, or feedback you'd like to provide, feel free to use the mailing list: code-quality@python.org
We would love to hear from you. Additionally, if you have a feature you'd like to suggest, the mailing list would be the best place for it.
Flake8 Documentation <http://flake8.pycqa.org/en/latest/>
_
GitLab Project <https://gitlab.com/pycqa/flake8>
_
All (Open and Closed) Issues <https://gitlab.com/pycqa/flake8/issues?scope=all&sort=updated_desc&state=all>
_
Code-Quality Archives <https://mail.python.org/mailman/listinfo/code-quality>
_
Code of Conduct <http://flake8.pycqa.org/en/latest/internal/contributing.html#code-of-conduct>
_
Getting Started Contributing <http://flake8.pycqa.org/en/latest/internal/contributing.html>
_
Flake8 was created by Tarek Ziadé and is currently maintained by Ian Cordasco <http://www.coglib.com/~icordasc/>
_
FAQs
the modular source code checker: pep8 pyflakes and co
We found that flake9 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.