<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Chainguard Libraries for Python on</title><link>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/</link><description>Recent content in Chainguard Libraries for Python on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Wed, 09 Apr 2025 08:04:00 +0000</lastBuildDate><atom:link href="https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/index.xml" rel="self" type="application/rss+xml"/><item><title>Chainguard Libraries for Python overview</title><link>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/overview/</link><pubDate>Wed, 09 Apr 2025 04:00:00 +0000</pubDate><guid>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/overview/</guid><description>Introduction Chainguard Libraries for Python provides enhanced security for the vast Python ecosystem by rebuilding PyPI packages with comprehensive supply chain protection and automated patching. With over 600,000 packages on the Python Package Index (PyPI) serving application development, machine learning, and data science needs, Chainguard addresses the critical security challenges of depending on packages from untrusted sources by rebuilding them within the controlled Chainguard Factory environment. In addition, Chainguard eliminates security risk by remediating High and Critical vulnerabilities across older package versions where upstream maintainers are not able to prioritize fixes.</description></item><item><title>Global configuration</title><link>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/global-configuration/</link><pubDate>Tue, 25 Mar 2025 08:04:00 +0000</pubDate><guid>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/global-configuration/</guid><description>Python library consumption in a large organization is typically managed by a repository manager. Commonly used repository manager applications are Cloudsmith, JFrog Artifactory, and Sonatype Nexus Repository. The repository manager acts as a single point of access for developers and development tools to retrieve the required libraries.
At a high level, adopting the use of Chainguard Libraries consists of the following steps:
Add Chainguard Libraries as a remote repository for library retrieval.</description></item><item><title>Build configuration</title><link>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/build-configuration/</link><pubDate>Tue, 25 Mar 2025 08:04:00 +0000</pubDate><guid>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/build-configuration/</guid><description>The configuration for the use of Chainguard Libraries depends on how you&amp;rsquo;ve set up your build tools and CI/CD workflows. At a high level, adopting the use of Chainguard Libraries in your development, build, and deployment workflows involves the following steps:
If you or an administrator have not done so already, set up your organization&amp;rsquo;s repository manager to use Chainguard Libraries for Python. Log into your organization&amp;rsquo;s repository manager and retrieve credentials for the build tool you are configuring.</description></item><item><title>Management and maintenance</title><link>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/management/</link><pubDate>Tue, 25 Mar 2025 08:04:00 +0000</pubDate><guid>https://deploy-preview-3174--ornate-narwhal-088216.netlify.app/chainguard/libraries/python/management/</guid><description>Chainguard Libraries for Python operates transparently after completing the global configuration and build configuration, automatically providing security-enhanced versions of your PyPI dependencies. New packages and versions are retrieved from Chainguard&amp;rsquo;s hardened repository when available, while PyPI and other configured repositories provide fallback access to ensure continuous development workflow without interruption.
The following sections detail optional management, maintenance, and auditing steps on the repository manager and the build tool.
Source verification You can verify what artifacts are retrieved from the Chainguard Libraries repository on a global level:</description></item></channel></rss>