
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
p3g
Advanced tools
This version is fork from https://github.com/TezRomacH/python-package-template. As a comparison, the current project provides better compatibility with Windows and faster lint construction. And a more lightweight way to create.
If you don't want to read the whole README, just click the Use this template button and start coding your Python package right now! 🚀
pip install p3g -U
p3g generate
For complete documentation, visit: https://p3g.zeeland.top
In this cookiecutter 🍪 template we combine state-of-the-art libraries and best development practices for Python.
Python 3.7 and higher.Poetry as a dependencies manager. See configuration in pyproject.toml and setup.cfg.ruff to replace black, isort and pyupgrade.pre-commit hooks with code-formatting.ruff; docstring checks with darglint; security checks with safety and banditpytest..editorconfig, .dockerignore, and .gitignore. You don't have to worry about those things.GitHub integration: issue and pr templates.Github Actions with predefined build workflow as the default CI/CD.Makefile. More details in makefile-usage.@dependabot. You only need to enable it.Release Drafter. You may see the list of labels in release-drafter.yml. Works perfectly with Semantic Versions specification.LICENSE, CONTRIBUTING.md, CODE_OF_CONDUCT.md, and SECURITY.md are generated automatically.Stale bot that closes abandoned issues after a period of inactivity. (You will only need to setup free plan). Configuration is here.Release Drafter.To begin using the template consider updating p3g
pip install -U p3g
then go to a directory where you want to create your project and run:
p3g generate
Template generator will ask you to fill some variables.
The input variables, with their default values:
| Parameter | Default value | Description |
|---|---|---|
project_name | python-project | Check the availability of possible name before creating the project. |
project_description | based on the project_name | Brief description of your project. |
organization | based on the project_name | Name of the organization. We need to generate LICENCE and to specify ownership in pyproject.toml. |
license | MIT | One of MIT, BSD-3, GNU GPL v3.0 and Apache Software License 2.0. |
minimal_python_version | 3.7 | Minimal Python version. One of 3.7, 3.8 and 3.9. It is used for builds, GitHub workflow and formatters (black, isort and pyupgrade). |
github_name | based on the organization | GitHub username for hosting. Also used to set up README.md, pyproject.toml and template files for GitHub. |
email | based on the organization | Email for CODE_OF_CONDUCT.md, SECURITY.md files and to specify the ownership of the project in pyproject.toml. |
version | 0.1.0 | Initial version of the package. Make sure it follows the Semantic Versions specification. |
line_length | 88 | The max length per line (used for codestyle with black and isort). NOTE: This value must be between 50 and 300. |
using_tsinghua_mirror_source | false | The tsinghua poetry mirror source |
create_example_template | cli | If cli is chosen generator will create simple CLI application with Typer and Rich libraries. One of cli, none |
All input values will be saved in the cookiecutter-config-file.yml file so that you won't lose them. 😉
Your project will contain README.md file with instructions for development, deployment, etc. You can read the project README.md template before.
poetryBy running pip install poetry & make install
After you create a project, it will appear in your directory, and will display a message about how to initialize the project.
pre-commitpre-commit is already installed if you initialize git repo before running make install. If it fails without initialization, run make install again to install pre-commit to .git.
Want to know more about Poetry? Check its documentation.
Poetry's commands are very intuitive and easy to learn, like:
poetry add numpy@latestpoetry run pytestpoetry publish --buildetc
If you set create_example_template to be cli the template comes with a cute little CLI application example. It utilises Typer and Rich for CLI input validation and beautiful formatting in the terminal.
After installation via make install (preferred) or poetry install you can try to play with the example:
poetry run <project_name> --help
poetry run <project_name> --name Roman
Building a new version of the application contains steps:
poetry version <version>. You can pass the new version explicitly, or a rule such as major, minor, or patch. For more details, refer to the Semantic Versions standard.GitHub.GitHub release.poetry publish --buildMakefile contains a lot of functions for faster development.
Install requirements:
make install
Pre-commit hooks coulb be installed after git init via
make pre-commit-install
Automatic formatting uses ruff.
make format
Codestyle checks only, without rewriting files:
make check-codestyle
Note:
check-codestyleusesruffanddarglintlibrary
make check-safety
This command launches Poetry integrity checks as well as identifies security issues with Safety and Bandit.
make check-safety
Run pytest
make test
Of course there is a command to run all linters in one:
make lint
the same as:
make check-codestyle && make test && make check-safety
make docker-build
which is equivalent to:
make docker-build VERSION=latest
Remove docker image with
make docker-remove
More information about docker.
Delete pycache files
make pycache-remove
Remove package build
make build-remove
Delete .DS_STORE files
make dsstore-remove
Remove .mypycache
make mypycache-remove
Or to remove all above run:
make cleanup
Well, that's up to you 💪🏻. I can only recommend the packages and articles that helped me.
Typer is great for creating CLI applications.Rich makes it easy to add beautiful formatting in the terminal.Pydantic – data validation and settings management using Python type hinting.Loguru makes logging (stupidly) simple.tqdm – fast, extensible progress bar for Python and CLI.IceCream is a little library for sweet and creamy debugging.orjson – ultra fast JSON parsing library.Returns makes you function's output meaningful, typed, and safe!Hydra is a framework for elegantly configuring complex applications.FastAPI is a type-driven asynchronous web framework.Articles:
You can see the list of available releases on the GitHub Releases page.
We follow Semantic Versions specification.
We use Release Drafter. As pull requests are merged, a draft release is kept up-to-date listing the changes, ready to publish when you're ready. With the categories option, you can categorize pull requests in release notes using labels.
| Label | Title in Releases |
|---|---|
enhancement, feature | 🚀 Features |
bug, refactoring, bugfix, fix | 🔧 Fixes & Refactoring |
build, ci, testing | 📦 Build System & CI/CD |
breaking | 💥 Breaking Changes |
documentation | 📝 Documentation |
dependencies | ⬆️ Dependencies updates |
This template will continue to develop and follow the bleeding edge new tools and best practices to improve the Python development experience.
Here is a list of things that have yet to be implemented:
Codecov ?).PyPI when new GitHub release is created.MkDocs with Material Design theme and mkdocstrings.Radon.interrogateDockerfile linting with dockerfilelint.Sourcerer.EarthlyThis project is licensed under the terms of the MIT license. See LICENSE for more details.
This template was inspired by several great articles:
and repositories:
Cookiecutterwemake-python-packagecookiecutter-pypackagecdstGive them your ⭐️, these resources are amazing! 😉
@misc{python-package-template,
author = {Zeeland},
title = {Python Packages Project Generator},
year = {2023},
publisher = {GitHub},
journal = {GitHub repository},
howpublished = {\url{https://github.com/Undertone0809/python-package-template}}
}
[](https://github.com/Undertone0809/python-package-template)
FAQs
Python Packages Project Generator
We found that p3g demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.