pinlint is a command-line static analysis tool that validates Python requirements.txt or similar files to ensure every package has both a version pin and a cryptographic hash. It is designed for use in CI pipelines and as a pre-commit hook to enforce reproducible builds and mitigate supply-chain security risks. The tool is open source under the MIT license.
pinlint is a Developer Tools project. It focuses on ensuring Python dependency files are fully pinned with versions and hashes to prevent supply-chain attacks and ensure reproducible builds. pinlint is an open-source project aimed at developers. pinlint is open source under the MIT license. pinlint is available on the command line.
Behind pinlint is Amaar Mc, and it first shipped in 2026. The project is developed in the open on GitHub with 14 commits in the last 90 days. Among its 5 catalogued features are Requirements Linting, Version Pinning Check, and Hash Pinning Check.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do