Package manager

PyPI Configuration

PyPI configuration files can contain package publishing credentials and repository tokens.

Metadata

  • id: package-manager.pypirc
  • category: package-manager
  • sensitivity: critical
  • subcategory: pypi
  • artifact types: credential, configuration
  • tags: pypi, python

Path Matchers

PathKindPlatforms
%USERPROFILE%\.pypircfilewindows
$HOME/.pypircfilelinux, macos

Content Indicators

Literal strings:

  • username
  • password
  • repository

Credential Types

  • password
  • api-token

Impact

  • credential_access

References

On this page