<!-- llms-explorer concept facts · https://llms-explorer.com/tree/python-supply-chain-application-security/ · pack 2026-09-08 · ~7289 tokens -->

# Python Supply-Chain & Application Security

> Python application security splits into two layers that share one toolchain:

Parent: [Python Patterns and Best Practices](https://llms-explorer.com/tree/python-patterns-and-best-practices/) · 15 facets · 93 facts · page: https://llms-explorer.com/tree/python-supply-chain-application-security/

## Overview

- Python application security splits into two layers that share one toolchain: — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#overview)
  - Application security (SAST) - find vulnerabilities in your own code (bandit). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#overview)
  - Supply-chain security - defend the dependencies and the path your artifacts travel: know what you ship (SBOM), know if it is vulnerable (pip-audit), prove where it came from (sigstore/PEP 740 attestations), and guarantee you install exactly what you locked (hash pinning). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#overview)
- The canonical layered ("defense in depth") posture for a 2026 Python project: pin + hash dependencies → audit them in CI (pip-audit) → SAST-scan your code (bandit) → generate an SBOM → publish with Trusted Publishing + attestations. Each layer closes a gap the others cannot; none is sufficient alone (hash pinning, for example, will faithfully pin a package that was already malicious on day one). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#overview)
- The four foundational PyPA/PyCQA tools - pip-audit, bandit, pip hash mode, and the PEP 740 attestation chain - are free, open source, and require no account or API key for the scanning paths. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#overview)

## 1. Dependency auditing — pip-audit

- What it is: the official PyPA tool that audits Python environments, requirements files, and dependency trees for packages with known vulnerabilities (SCA - software composition analysis). Maintained by the Python Packaging Authority. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#1-dependency-auditing-pip-audit)
- Vulnerability sources: queries the PyPA Advisory Database and the OSV database. Select via --vulnerability-service {osv,pypi} (osv is default); --osv-url points at a custom OSV mirror. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#1-dependency-auditing-pip-audit)
- Input modes: audit the live environment (pip-audit), a requirements file (pip-audit -r requirements.txt), or a PEP 751 lockfile (pylock.toml, supported in recent releases). For fully pinned input, skip resolution with --no-deps (pinned, no hashes) or --require-hashes (pinned + hashed). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#1-dependency-auditing-pip-audit)
- Auto-fix: --fix upgrades vulnerable pins in place to the first non-vulnerable version; --dry-run previews. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#1-dependency-auditing-pip-audit)
- Output / SBOM: -f {columns,json,cyclonedx-json,cyclonedx-xml,markdown} - it can itself emit a CycloneDX SBOM with vulnerabilities linked to affected components via the affects field. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#1-dependency-auditing-pip-audit)

## 2. SBOM generation (Software Bill of Materials)

- Why: a machine-readable inventory of every component (incl. transitive) so downstream consumers and scanners can answer "am I affected by CVE-X?" Increasingly required by regulation (US EO 14028, EU Cyber Resilience Act). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)
  - CycloneDX - security-first; built for vulnerability identification and outdated-dependency analysis. Dominant in the Python ecosystem (of the ~1.6% of PyPI packages shipping an SBOM, effectively all are CycloneDX). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)
  - SPDX - license-compliance-first; richer license fields. ISO/IEC 5962 standard. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)
  - cyclonedx-py (the cyclonedx-bom distribution) - the most accurate Python-native generator; reads environments, requirements.txt, poetry.lock, Pipfile.lock, and pip lockfiles with proper hash support. Subcommands: cyclonedx-py environment, ... requirements, ... poetry. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)
  - uv export --format cyclonedx - straight from uv.lock (see references/uv-python-toolchain.md). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)
  - Syft (Anchore) - ecosystem-agnostic; SBOMs from filesystems/container images; emits both CycloneDX and SPDX. Use for the container layer. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)
  - lib4sbom - parse/convert SBOMs between SPDX and CycloneDX. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)
- PEP 770 (SBOMs inside wheels): standardizes shipping SBOMs in a wheel's .dist-info/sboms/ directory, so consumers get the SBOM automatically on pip install. Solves the "phantom dependency" problem (bundled non-Python libs invisible to Python-level tools). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2-sbom-generation-software-bill-of-materials)

## 3. Static application security testing — bandit

- What it is: the PyCQA SAST linter for Python. Builds an AST per file and runs security plugins against it. Catches insecure patterns before runtime. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#3-static-application-security-testing-bandit)
- B-codes (rule families): B1xx general (B101 assert, B102 exec, B105/B106/B107 hardcoded passwords, B108 temp-file); B3xx blacklisted calls/imports (B301 pickle, B303/B304 weak MD5/SHA1 / insecure ciphers, B307 eval, B311 non-crypto random); B5xx crypto/cert (B501 verify=False); B6xx injection (B602 subprocess with shell=True, B608 SQL string-build); plus newer AI/ML checks (B614 unsafe torch.load, B615 insecure Hugging Face download). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#3-static-application-security-testing-bandit)
- Severity × confidence: every finding has a severity (LOW/MEDIUM/HIGH) and a confidence (how sure bandit is it is real). Filter both: --severity-level medium --confidence-level medium is the standard noise cut. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#3-static-application-security-testing-bandit)
- Config: [tool.bandit] in pyproject.toml or a .bandit INI / bandit.yaml - set exclude_dirs, skips (e.g. B101), tests (allowlist), per-plugin options. Inline suppression: # nosec B602 on the offending line (scope the code - bare # nosec is an anti-pattern). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#3-static-application-security-testing-bandit)
- Baseline workflow: bandit -r src/ -f json -o baseline.json, then bandit -r src/ -b baseline.json so CI only flags newly introduced issues - the practical way to adopt bandit on a legacy codebase without a wall of red. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#3-static-application-security-testing-bandit)

## 4. Provenance — sigstore, PEP 740 attestations & Trusted Publishing

- The problem PGP couldn't solve: PyPI deprecated/removed PGP signatures - almost nobody verified them and key management was broken. PEP 740 replaces them with identity-based signing. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#4-provenance-sigstore-pep-740-attestations-trusted-publishing)
- Trusted Publishing (OIDC): instead of a long-lived API token, a CI workflow (GitHub Actions, GitLab CI, etc.) presents a short-lived OIDC identity to PyPI and receives a short-lived upload token. No secret to leak/rotate. This is the prerequisite layer. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#4-provenance-sigstore-pep-740-attestations-trusted-publishing)
- PEP 740 digital attestations: cryptographically signed, publicly verifiable statements about a package (notably build provenance). Built on Sigstore with short-lived signing keys bound to the OIDC identity (keyless signing → Rekor transparency log), and the payload follows the in-toto Attestation Framework. Because there is no private key sitting around, key loss/theft is largely designed out. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#4-provenance-sigstore-pep-740-attestations-trusted-publishing)
- How to get it: if you already publish via Trusted Publishing with pypa/gh-action-pypi-publish v1.11.0+, build provenance attestations are generated and uploaded automatically - usually zero code change. PyPI exposes attestations + Trusted-Publishing metadata as provenance objects through the HTML and JSON Simple APIs. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#4-provenance-sigstore-pep-740-attestations-trusted-publishing)
- Verification: the pypi-attestations CLI / library verifies a downloaded file's attestation against the expected identity. Track ecosystem adoption at the "Are we PEP 740 yet?" dashboard. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#4-provenance-sigstore-pep-740-attestations-trusted-publishing)

## 5. Hash-pinned dependencies (reproducible, tamper-evident installs)

- What it does: records a cryptographic digest (--hash=sha256:…) for every artifact. On install, pip recomputes and compares; a mismatch aborts the install. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)
- What it protects against: tampering in transit, in a cache, or on a compromised mirror; a PyPI or TLS-chain compromise; a package whose content changes without a version bump. It is the integrity backstop. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)
- What it does NOT protect against: a package that is malicious from the first install (you just pin the malicious hash), and it says nothing about whether a dependency is vulnerable (that's pip-audit's job). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)
- Generating hashes: — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)
  - pip-tools: pip-compile --generate-hashes requirements.in → fully pinned requirements.txt with --hash lines. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)
  - uv: uv lock (hashes in uv.lock) or uv pip compile --generate-hashes / uv export --format requirements-txt (see references/uv-python-toolchain.md). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)
  - Pipenv records hashes in Pipfile.lock natively. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)
- Enforcing: pip install --require-hashes -r requirements.txt. --require-hashes is auto-enabled if any line has a hash; it then demands every requirement be pinned (==) and hashed, including transitive deps - which is why a hash-generating compiler is mandatory. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#5-hash-pinned-dependencies-reproducible-tamper-evident-installs)

## Methodology — layered project posture

- Lock + hash every dependency (uv lock or pip-compile --generate-hashes); install with --require-hashes (uv sync enforces the lock). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#methodology-layered-project-posture)
- Audit in CI - pip-audit -r requirements.txt (or against the lockfile); fail the build on findings; use --fix --dry-run to triage upgrades. Do not auto-update to latest blindly. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#methodology-layered-project-posture)
- SAST in CI - bandit -r src/ -c pyproject.toml; run HIGH-severity only as a blocking gate, full set as non-blocking/local; adopt via a baseline. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#methodology-layered-project-posture)
- Generate an SBOM as a build artifact (cyclonedx-py for the app, syft for the image); attach to the release; PEP 770 to embed in wheels you publish. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#methodology-layered-project-posture)
- Publish with provenance - Trusted Publishing (OIDC, no token) + automatic PEP 740 attestations via gh-action-pypi-publish. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#methodology-layered-project-posture)
- Harden the pipeline itself - pin third-party Actions to a full commit SHA, run zizmor on workflows, track posture with OpenSSF Scorecard. The supply chain includes your CI, not just your deps. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#methodology-layered-project-posture)

## Anti-Patterns

- Trusting hash pinning to vet packages. Hashes guarantee integrity, not safety. Pair with pip-audit (known CVEs) and review for first-time deps. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)
- Blanket # nosec with no rule code - silently suppresses all future findings on that line. Always # nosec Bxxx. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)
- Running bandit at default severity in CI - B101 assert noise drowns real findings; teams disable the whole tool. Filter to medium/high and use a baseline. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)
- Long-lived PyPI API tokens in CI secrets. Migrate to Trusted Publishing; a leaked token (cf. the 2025 GhostAction theft of 3,300+ secrets) is a full publish compromise. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)
- Unpinned third-party GitHub Actions (@v4/@main). A tag can be force-moved to malicious code. Pin to a full commit SHA; verify with zizmor. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)
- Partial hashing. --require-hashes requires every (incl. transitive) requirement pinned + hashed; a half-hashed file fails. Always regenerate via a compiler. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)
- Generating an SBOM once and never again. An SBOM is only useful if regenerated on every release and stored as an artifact you can query when a new CVE drops. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)
- Auditing only direct dependencies. Most CVEs and most supply-chain attacks ride in transitive deps; audit the full resolved tree/lockfile. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#anti-patterns)

## Troubleshooting

- pip-audit exits non-zero but you must ship now: triage with --fix --dry-run; if a finding is a known false positive / unfixable, --ignore-vuln <GHSA/PYSEC id> (document why). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#troubleshooting)
- pip install --require-hashes fails "hashes are required for all packages": a transitive dep is unpinned/unhashed - regenerate with pip-compile --generate-hashes or uv export. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#troubleshooting)
- Hash mismatch on install: the artifact differs from the locked hash - could be a mirror/cache problem or tampering. Do not bypass; re-resolve from PyPI and compare. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#troubleshooting)
- bandit flags B608 SQL or B602 subprocess you know is safe: restructure to remove the pattern (parameterized query, shell=False + list args) rather than suppress - the rule is usually right. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#troubleshooting)
- Attestations not appearing on PyPI: confirm permissions: id-token: write, gh-action-pypi-publish ≥ 1.11.0, and that the repo is registered as a Trusted Publisher (not token auth). — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#troubleshooting)
- SBOM missing bundled native libs ("phantom dependencies"): Python-level generators can't see vendored C libs; use Syft on the built artifact/image, and adopt PEP 770 for wheels you publish. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#troubleshooting)

## 2025-2026 threat landscape (why this matters)

- Typosquatting & dependency confusion remain the top vectors: malicious packages named like requests/tensorflow (500+ typosquats in waves), and internal-name confusion pulling a public package over a private one. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2025-2026-threat-landscape-why-this-matters)
- 2025 PyPI phishing - noreply@pypj.org (note the j) proxy credential harvester targeting maintainers. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2025-2026-threat-landscape-why-this-matters)
- GhostAction (Sept 2025) - injected workflows across 570+ repos, exfiltrating 3,300+ secrets incl. PyPI/npm/AWS tokens - the canonical case for Trusted Publishing over tokens and for pinning/auditing CI. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2025-2026-threat-landscape-why-this-matters)
- Shai-Hulud worm (Nov 2025) - cross-ecosystem (npm-origin) worm that also hit PyPI via monorepos sharing credentials. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2025-2026-threat-landscape-why-this-matters)
- PyPI processed 2,000+ malware reports in 2025, 66% within 4 hours - fast, but reactive; your pinning + audit + provenance layers are the proactive defense. — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#2025-2026-threat-landscape-why-this-matters)

## References (sources)

- pip-audit - https://github.com/pypa/pip-audit · https://pypi.org/project/pip-audit/ — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- PyPA Advisory Database - https://github.com/pypa/advisory-database · OSV - https://osv.dev — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- bandit - https://bandit.readthedocs.io · https://pypi.org/project/bandit/ (PyCQA) — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- pip repeatable installs / --require-hashes - https://pip.pypa.io/en/stable/topics/repeatable-installs/ — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- pip-tools --generate-hashes - https://github.com/jazzband/pip-tools — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- CycloneDX Python (cyclonedx-py) - https://github.com/CycloneDX/cyclonedx-python · https://cyclonedx-bom-tool.readthedocs.io — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- Syft - https://github.com/anchore/syft · lib4sbom - https://pypi.org/project/lib4sbom/ — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- PEP 740 (digital attestations) - https://peps.python.org/pep-0740/ · PEP 770 (SBOMs in packages) — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- PyPI attestations docs - https://docs.pypi.org/attestations/ · blog.pypi.org/posts/2024-11-14-pypi-now-supports-digital-attestations/ — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- Trail of Bits "Attestations: a new generation of signatures on PyPI" - https://blog.trailofbits.com/2024/11/14/attestations-a-new-generation-of-signatures-on-pypi/ — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- "Are we PEP 740 yet?" - https://trailofbits.github.io/are-we-pep740-yet/ · pypi-attestations - https://pypi.org/project/pypi-attestations/ — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- OpenSSF Scorecard - https://scorecard.dev · https://github.com/ossf/scorecard · ossf/malicious-packages — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- zizmor (GitHub Actions SAST) - https://docs.zizmor.sh — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- bernat.tech "Defense in Depth: A Practical Guide to Python Supply Chain Security" — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)
- sbomify Python SBOM guide - https://sbomify.com/guides/python/ — [source](https://llms-explorer.com/sources/mdb-context-hub/python-supply-chain-security/#references-sources)

## Where this helps

- Before a security review or compliance audit that requires a Software Bill of Materials for every shipped Python application or library. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Hardening a CI/CD pipeline against dependency-confusion or typosquatting attacks by pinning hashes and verifying provenance instead of trusting whatever `pip install` resolves at build time. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Publishing a package to PyPI, where Trusted Publishing and PEP 740 attestations let downstream users verify the artifact actually came from your CI run. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Scanning application code for insecure patterns — hardcoded secrets, shell injection, unsafe deserialization — with bandit as part of a pre-merge or pre-release gate. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Investigating whether a known CVE in a transitive dependency actually affects your application, using pip-audit's dependency-graph-aware reporting. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Project ideas

- Wire pip-audit and bandit into a pre-commit hook or CI job so dependency and code-level findings block a merge instead of surfacing after release. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Generate an SBOM for an existing project and diff it release-over-release to see exactly what dependency changes actually shipped. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Convert a project's requirements to hash-pinned dependencies and set up an automated renewal workflow so pins stay current without losing tamper-evidence. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Set up Trusted Publishing for a package you maintain on PyPI, replacing a long-lived API token with short-lived OIDC-issued credentials tied to your CI provider. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Common mistakes

- Running `pip install` with unpinned version ranges in production, letting a compromised or yanked upstream release get pulled in automatically on the next build. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Treating an SBOM as a one-time compliance checkbox instead of a living artifact regenerated on every release, so it drifts from what's actually shipped. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Storing long-lived PyPI API tokens in CI secrets instead of adopting Trusted Publishing, leaving a static credential that can be exfiltrated and reused indefinitely. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Running bandit once and never re-running it in CI, so a newly introduced insecure pattern ships undetected. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- Hash-pinning increases maintenance overhead — every legitimate dependency bump requires regenerating pins, which can slow routine patching if the workflow isn't automated. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- SBOM-generation tools don't always agree on format or depth of transitive-dependency resolution, so an SBOM from one tool isn't always directly comparable to one from another. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- pip-audit relies on vulnerability databases like OSV that lag real-world disclosure, so a freshly disclosed CVE may not appear in a scan for hours or days. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Static analysis tools like bandit produce false positives on intentional patterns, so blind CI gating on any finding can block legitimate code without a triage step. — [source](https://llms-explorer.com/tree/python-supply-chain-application-security/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Context files

- [Python Supply-Chain & Application Security](https://llms-explorer.com/downloads/sources/mdb-context-hub/python-supply-chain-security.md)
