Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
jupyterlab-requirements
Advanced tools
.. image:: https://img.shields.io/github/v/tag/thoth-station/jupyterlab-requirements?style=plastic :target: https://github.com/thoth-station/jupyterlab-requirements/releases :alt: GitHub tag (latest by date)
.. image:: https://img.shields.io/pypi/v/jupyterlab-requirements?style=plastic :target: https://pypi.org/project/jupyterlab-requirements :alt: PyPI - Module Version
.. image:: https://img.shields.io/pypi/l/jupyterlab-requirements?style=plastic :target: https://pypi.org/project/jupyterlab-requirements :alt: PyPI - License
.. image:: https://img.shields.io/pypi/dm/jupyterlab-requirements?style=plastic :target: https://pypi.org/project/jupyterlab-requirements :alt: PyPI - Downloads
This is a JupyterLab extension for dependency management and optimization created to guarantee reproducibility of Jupyter notebooks.
This extension provides management of dependencies for JupyterLab notebooks.
The main goals of the project are the following:
NOTE: The requirements are optimized using the Thoth <https://thoth-station.ninja/>
__ resolution engine.
This extension requires:
The extension can be installed via pip or Pipenv from PyPI <https://pypi.org/project/jupyterlab-requirements>
__:
.. code-block:: console
pip install jupyterlab-requirements
You can initialize JupyterLab and start using it.
.. code-block:: console
jupyter lab
If you are seeing the frontend extension, but it is not working, check that the server extension is enabled:
.. code-block:: console
jupyter server extension list
If the server extension is installed and enabled, but you are not seeing the frontend extension, check the frontend extension is installed:
.. code-block:: console
jupyter labextension list
There are 3 ways to interact with this extension:
%horus magic commands <https://github.com/thoth-station/jupyterlab-requirements/blob/master/docs/source/horus-magic-commands.md>
__ directly in your notebook's cells.
horus CLI <https://github.com/thoth-station/jupyterlab-requirements/blob/master/docs/source/horus-cli.md>
__ from terminal or integrated in pipelines.
jupyterlab-requirements UI <https://github.com/thoth-station/jupyterlab-requirements/blob/master/docs/source/jupyterlab-requirements-ui.md>
__ accessible through Manage Dependencies
button that appears in the notebook when it is opened in JupyteLab.
There are currently two resolution engines available in the extension:
Thoth <https://thoth-station.ninja/>
__
Pipenv <https://github.com/pypa/pipenv>
__
NOTE: Thoth is used by default and Pipenv can be triggered with flags or run as backup automatically.
NOTE: Currently this extension supports only Python
kernels.
Using the Thoth resolution engine you can request an optimized software stack that satisfies your requirements.
You can choose the type of recommendation that better fits your needs:
You can find more information and updates here <https://thoth-station.ninja/recommendation-types/>
__.
Thoth resolution engine is able to provide an optimized software stack based on the runtime environment you are using (several inputs are used, if you want to know more, have a look here here <https://github.com/thoth-station/adviser>
__).
In general different runtime environment will provide different effect on you application (e.g. more performance), therefore we include these information in the notebook metadata so that other can find out what runtime environment has been used to run a certain notebook.
You can select the runtime environment to be used for the recommendation selecting:
Operating System Name
Operating System Version
Python Interpreter Version
NOTE: Those parameters are autodiscovered by the extension and assigned to your environment, you can customize them if you are interested.
Once lock file is created using any of available resolution engines, the dependencies will be installed in the virtualenv using
micropipenv <https://pypi.org/project/micropipenv/>
__.
The virtual environment created and assigned to the kernel to be used for your notebook according to your dependencies requirements can be checked using the following command from a terminal:
.. code-block:: console
cat ~/.local/share/thoth/kernels/{kernel_name}
The dependencies stored in the notebook metadata can be also stored into overlays
folder using the kernel name by default.
If you want to know more about the use of overlays, have a look micropipenv <https://github.com/thoth-station/thamos#support-for-multiple-runtime-environments>
.
If you want to see a practical example on the use of overlays and how to create them from your notebook, you can check this tutorial <https://github.com/AICoE/overlays-for-ai-pipeline-tutorial>
.
If you have too many kernels, you can remove them directly from the JupyterLab menu under Kernel Section. This plugin is provided from this extension.
You can use this extension for each of your notebook to guarantee they have the correct dependencies files required for reproducibility and shareability. In this way, all the dependencies information required to repeat the environment are shipped with the notebook. In the notebook metadata you will find:
.. list-table:: :widths: 25 40 :header-rows: 1
requirements
requirements
dependency resolution engine
configuration file
All this information can allow reproducibility of the notebook.
NOTE: You will need NodeJS to build the extension package.
The jlpm
command is JupyterLab's pinned version of
yarn <https://yarnpkg.com/>
__ that is installed with JupyterLab. You may use
yarn
or npm
in lieu of jlpm
below.
Fork this repository
Clone the origin repo to your local environment
.. code-block:: console
git clone git@github.com:thoth-station/jupyterlab-requirements.git
Change directory to the jupyterlab-requirements directory
Create new virtualenv
.. code-block:: console
pipenv install --dev
.. code-block:: console
pipenv shell
All following commands needs to be run from the virtualenv created and accessed with command in point 5.
.. code-block:: console
pip install -ve . --no-cache-dir
.. code-block:: console
jupyter labextension develop . --overwrite
.. code-block:: console
jupyter serverextension enable --py jupyterlab-requirements --sys-prefix
.. code-block:: console
jlpm run build
You can watch the source directory and run JupyterLab at the same time in different terminals to watch for changes in the extension's source and automatically rebuild the extension.
The following command watch the source directory in one terminal, automatically rebuilding when needed.
.. code-block:: console
jlpm run watch
The following command run JupyterLab in another terminal.
.. code-block:: console
jupyter lab
With the watch command running, every saved change will immediately be built locally and available in your running JupyterLab. Refresh JupyterLab to load the change in your browser (you may need to wait several seconds for the extension to be rebuilt).
By default, the jlpm run build
command generates the source maps for this extension to make it easier to debug using the browser dev tools. To also generate source maps for the JupyterLab core extensions, you can run the following command:
.. code-block:: console
jupyter lab build --minimize=False
.. code-block:: console
python3 setup.py test
When all tests passed and you are ready with a new contribution open a Pull Request!! We are very happy to receive contributions from the community!
v0.13.0 <https://www.youtube.com/watch?v=7BuxODwRKq8>
__ [Nov 22 2021]
v0.11.0 <https://www.youtube.com/watch?v=SFui8yrMVjw>
__ [Sep 13 2021]
v0.10.4 <https://www.youtube.com/watch?v=FjVxNTXO70I>
__ [Aug 10 2021]
v0.9.2 <https://www.youtube.com/watch?v=fW0YKugL26g&t>
__ [Jul 19 2021]
v0.8.0 <https://www.youtube.com/watch?v=DubjY5Ib4fA>
__ [Jul 9 2021]
v0.7.4 <https://www.youtube.com/watch?v=YQIhuB16DuM>
__ [Jun 22 2021]
v0.5.0 <https://www.youtube.com/watch?v=A3W48aHubkE>
__ [Mar 15 2021]
v0.3.7 <https://www.youtube.com/watch?v=-_dtDAAyMlU&t>
__ [Feb 10 2021]
v0.1.0 <https://www.youtube.com/watch?v=IBzTOP4TCdA>
__ [Dec 8 2020]
.. code-block:: console
pip uninstall jupyterlab-requirements
FAQs
JupyterLab Extension for dependency management and optimization
We found that jupyterlab-requirements demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.