Package manager

pip Configuration

pip configuration files can include package index URLs with embedded credentials.

Metadata

  • id: package-manager.pip-config
  • category: package-manager
  • sensitivity: high
  • subcategory: pip
  • artifact types: configuration, credential
  • tags: pip, python

Path Matchers

PathKindPlatforms
%APPDATA%\pip\pip.inifilewindows
$HOME/.pip/pip.conffilelinux, macos
$XDG_CONFIG_HOME/pip/pip.conffilelinux, macos

Content Indicators

Literal strings:

  • index-url
  • extra-index-url

Credential Types

  • password
  • access-token

Impact

  • credential_access

References

On this page