
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
Roboflow provides everything you need to build and deploy computer vision models. roboflow-python is the official Roboflow Python package. roboflow-python enables you to interact with models, datasets, and projects hosted on Roboflow.
With this Python package, you can:
The Python package is documented on the official Roboflow documentation site. If you are developing a feature for this Python package, or need a full Python library reference, refer to the package developer documentation.
You will need to have Python 3.8 or higher set up to use the Roboflow Python package.
Run the following command to install the Roboflow Python package:
pip install roboflow
For desktop features, use:
pip install "roboflow[desktop]"
You can also install the Roboflow Python package from source using the following commands:
git clone https://github.com/roboflow-ai/roboflow-python.git
cd roboflow-python
python3 -m venv env
source env/bin/activate
pip install .
By installing roboflow python package you can use some of its functionality in the command line (without having to write python code). See CLI-COMMANDS.md
To use the Roboflow Python package, you first need to authenticate with your Roboflow account. You can do this by running the following command:
import roboflow
roboflow.login()
You can also authenticate with an API key by using the following code:
import roboflow
rf = roboflow.Roboflow(api_key="")
Below are some common methods used with the Roboflow Python package, presented concisely for reference. For a full library reference, refer to the Roboflow API reference documentation.
import roboflow
roboflow.login()
rf = roboflow.Roboflow()
# create a project
rf.create_project(
project_name="project name",
project_type="project-type",
license="project-license" # "private" for private projects
)
workspace = rf.workspace("WORKSPACE_URL")
project = workspace.project("PROJECT_URL")
version = project.version("VERSION_NUMBER")
# upload a dataset
workspace.upload_dataset(
dataset_path="./dataset/",
num_workers=10,
dataset_format="yolov8", # supports yolov8, yolov5, and Pascal VOC
project_license="MIT",
project_type="object-detection"
)
# upload model weights
version.deploy(model_type="yolov8", model_path=f”{HOME}/runs/detect/train/”)
# upload model weights - yolov10
# Before attempting to upload YOLOv10 models install ultralytics like this:
# pip install git+https://github.com/THU-MIG/yolov10.git
version.deploy(model_type="yolov10", model_path=f”{HOME}/runs/detect/train/”, filename="weights.pt")
# run inference
model = version.model
img_url = "https://media.roboflow.com/quickstart/aerial_drone.jpeg"
predictions = model.predict(img_url, hosted=True).json()
print(predictions)
The Roboflow Python library is structured using the same Workspace, Project, and Version ontology that you will see in the Roboflow application.
import roboflow
roboflow.login()
rf = roboflow.Roboflow()
workspace = rf.workspace("WORKSPACE_URL")
project = workspace.project("PROJECT_URL")
version = project.version("VERSION_NUMBER")
The workspace, project, and version parameters are the same as those you will find in the URL addresses at app.roboflow.com and universe.roboflow.com.
Within the workspace object you can perform actions like making a new project, listing your projects, or performing active learning where you are using predictions from one project's model to upload images to a new project.
Within the project object, you can retrieve metadata about the project, list versions, generate a new dataset version with preprocessing and augmentation settings, train a model in your project, and upload images and annotations to your project.
Within the version object, you can download the dataset version in any model format, train the version on Roboflow, and deploy your own external model to Roboflow.
We would love your input on how we can improve the Roboflow Python package! Please see our contributing guide to get started. Thank you 🙏 to all our contributors!
FAQs
Official Python package for working with the Roboflow API
We found that roboflow demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.