Skip to main content

Why Scan for Vulnerabilities?

Dependency vulnerabilities are a common attack vector. This page covers the data and practical mitigations.

Statistics​

  • 512,847 malicious packages detected on PyPI in 2024 (Sonatype)
  • 75% of organizations experienced a supply chain attack in 2024 (DeepStrike)
  • 82% of open source components flagged for poor maintenance or security flaws (ISACA)
  • $4.44M average data breach cost globally, $10.22M in the US (DeepStrike)

Recent PyPI Incidents​

PackageDateDescription
UltralyticsDec 2024GitHub Actions cache poisoning led to malicious releases via legitimate CI/CD
python-json-logger2025Abandoned dependency (46M monthly downloads) hijacked for RCE
LangflowMay 2025CVSS 9.8 RCE, added to CISA Known Exploited Vulnerabilities
sisawsAug 2025Typosquat of sisa package, delivered RAT malware

Case Study: Log4Shell​

Log4Shell (CVE-2021-44228) in December 2021 demonstrated the risk of transitive dependencies.

  • CVSS 10.0, affected 93% of enterprise cloud environments
  • Most organizations were unaware they used Log4j - it was a transitive dependency
  • 45% patched within 10 days
  • 30-40% of downloads remained vulnerable one year later

The core issue: transitive dependencies are not visible without tooling.

Mitigations​

1. Dependency Visibility​

Track your full dependency tree, including transitive dependencies pulled in by direct dependencies.

2. Continuous Scanning​

New CVEs are published daily. Periodic audits miss vulnerabilities discovered between scans.

3. CI/CD Integration​

Automated scanning catches vulnerabilities before deployment.

4. Quarantine Detection​

PyPI quarantines malicious packages without full removal. Scanners should detect quarantine status.

PySentry Capabilities​

  • Multiple sources: PyPA, PyPI, OSV.dev vulnerability databases
  • PEP 792: Detects quarantined, deprecated, and archived packages
  • Transitive visibility: Flags transitive findings and names the top-level dependency that pulled them in
  • Performance: Rust implementation, sub-second scans
  • Output formats: human-readable, JSON, SARIF, and Markdown
  • CI-native: First-party GitHub Action with SARIF upload to Code Scanning and a compact job-summary report
  • Security policy: Per-group fail_on thresholds and package ignores, with a fail-closed policy for incomplete scans so results are never silently partial

Next Steps​

See the Quick Start Guide for setup instructions.