five

LowEndInsight-PyPI

收藏
DataCite Commons2020-12-07 更新2025-04-16 收录
下载链接:
https://ieee-dataport.org/open-access/lowendinsight-pypi
下载链接
链接失效反馈
官方服务:
资源简介:
The Python Packaging Index is an invaluable resource that is used by developers to improve their projects; however, there are glaring issues in its implementation that will hinder development until resolved. The Python Packaging Index (PyPI) is the official third-party software repository for Python where the majority of open-source Python packages are published. Each package has wheel and egg files accessible from the Python package management system PIP, as well as queryable metadata that contains important package information. The PyPI metadata provides key information such as package license, source code, and dependencies which are necessary for developers working with a given open-source package to ascertain its security and legal risks; however since PyPI currently does not support an effective means of tracking some of this information, it forces a developer to cope with uncertain risk if they wish to use open-source code. In its current state, Python open-source code facilitates project development at the risk of unknown vulnerabilities; however, developers should not be sacrificing efficiency for security. This dataset provides some insight into the PyPI ecosystem, using the LowEndInsight analyzer to process all packages, traverse from module to source code, and then identify potential risks. The dataset is the result of upstream HPC processing against the PyPI generated raw data.
提供机构:
IEEE DataPort
创建时间:
2020-12-07
5,000+
优质数据集
54 个
任务类型
进入经典数据集
二维码
社区交流群

面向社区/商业的数据集话题

二维码
科研交流群

面向高校/科研机构的开源数据集话题

数据驱动未来

携手共赢发展

商业合作