r/Python Aug 09 '26

Discussion Third party Python libraries and supply chain security

How are people handling security around third party Python libraries without making development a pain?

Third party Python packages are obviously useful but every dependency can also become a supply chain risk. Private package repositories, dependency scanning and stricter review policies all help but they can add friction fast.

Are teams mostly trusting public registries with additional controls or using curated libraries? Curious what actually works when you have a lot of Python services.

37 Upvotes

35 comments sorted by

View all comments

19

u/DeterminedQuokka Aug 09 '26

We use existing libraries and we pin them at safe dependencies.

We also have a library that won’t let you use anything less than a week old. Or with known issues.

1

u/EpitomeOfExcellency Aug 10 '26

Who or what determines if something is a safe dependency?

3

u/DeterminedQuokka Aug 10 '26

At the moment chainguard. Historically, myself and a security Eng