Beta Testing needed for my package Trustcheck
Catches supply-chain attacks by verifying cryptographic attestations before pip install.

Tests PyPI packages across 6 Python environments with live pass-rate dashboard.
Python developers and package maintainers
Requires.io · Depfu · PyPI Health
The watchdog pulls packages, attempts installs across multiple Python environments, runs basic import verification, and publishes results continuously. The dashboard is live at https://sovereignmail.org/pypiplace . Data is also broadcast over the Yggdrasil mesh network for anyone who wants to pull and verify it independently.
It's my first experiment running live on a free tier Oracle ARM instance.
I find it useful. And kinda cool. I'd love anybody who want to run it to do so.
https://github.com/PregnantPenguins789/vps-pypi-place https://github.com/PregnantPenguins789/yggcrawl
Catches supply-chain attacks by verifying cryptographic attestations before pip install.
Consolidates sigstore attestation verification and vulnerability scans into one pre-install CLI check.
nodei.co already does this for npm; this is the Python clone without differentiation.
PyPI package with zero description — no README, no docs, no idea what it does.
Real-time PyPI trends with Claude AI summaries, but analytics dashboards exist (npm trends, libraries.io).
Simulates governance policies without CUDA kernels or real vLLM schedulers.