dlint
Dlint is a tool for encouraging best coding practices and helping ensure Python code is secure.
Decision gist · record as of 2026-08-14
Yes, with conditions. Dlint is a solid choice for adding security-focused linting to Python projects if you already use flake8. The low install friction and permissive license make adoption straightforward. However, the aging maintenance status means you should verify compatibility with your current Python and flake8 versions before relying on it for critical security workflows. No known vulnerabilities are recorded.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires flake8 to be installed; dlint operates as a flake8 plugin and cannot run standalone.
- Low friction: pure Python wheel with only flake8 as a runtime dependency.
- Maintenance is aging—last release was 2024-10-31—but the repository remains active and unarchived.
License · maintenance · safety
BSD-3-Clause (permissive) — BSD-3-Clause is permissive; you can use, modify, and distribute dlint freely in commercial and private projects with minimal restrictions, provided you include the license notice.
last release 2024-10-31 (652 days) · last repo commit 2026-01-07 · 179 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 92,972 downloads/mo, #13,410 on PyPI
Alternatives
Verify before relying
pip install dlint
python -m flake8 --select=DUO /path/to/code- Whether the aging maintenance status affects compatibility with Python 3.14 or current flake8 versions.
- Coverage and completeness of security rules compared to other Python security linters.
- Performance impact when running dlint on large codebases.
What it is and what it does
Dlint extends flake8 with a set of linting rules designed to catch security vulnerabilities and enforce coding best practices in Python. It operates as a flake8 plugin, so it integrates directly into your existing flake8 workflow and can be run from the command line or integrated into CI pipelines and editor plugins. The rules are prefixed with DUO and flag patterns like exec() calls, unsafe deserialization, and other insecure coding practices.
The package is lightweight—it depends only on flake8—and supports Python 3.8.1 through 3.14. It can be used standalone via the CLI with the --select=DUO flag, embedded in editor linters, or integrated into continuous integration systems. Custom plugins can be built by following a simple naming convention.
Use it for
- Catch insecure patterns like exec() and eval() in code review before they reach production.
- Integrate security linting into CI/CD pipelines to enforce best practices across a codebase.
- Enable real-time inline feedback in editors during development.
- Enforce security standards across a team by running dlint in pre-commit hooks.
- Extend dlint with custom security rules via plugins for domain-specific vulnerabilities.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
Dlint is a solid choice for adding security-focused linting to Python projects if you already use flake8. The low install friction and permissive license make adoption straightforward. However, the aging maintenance status means you should verify compatibility with your current Python and flake8 versions before relying on it for critical security workflows. No known vulnerabilities are recorded.
Install
dlint on PyPI
Before you install
Low friction: pure Python wheel with only flake8 as a runtime dependency. Maintenance is aging—last release was 2024-10-31—but the repository remains active and unarchived.
Requires flake8 to be installed; dlint operates as a flake8 plugin and cannot run standalone.
License in practice
BSD-3-Clause is permissive; you can use, modify, and distribute dlint freely in commercial and private projects with minimal restrictions, provided you include the license notice.
Quickstart
pip install dlint
python -m flake8 --select=DUO /path/to/code
Verify before relying
- Whether the aging maintenance status affects compatibility with Python 3.14 or current flake8 versions.
- Coverage and completeness of security rules compared to other Python security linters.
- Performance impact when running dlint on large codebases.
Package facts
| License | BSD-3-Clause permissive |
| Python support | Supports the current Python release <4.0.0,>=3.8.1 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageflake8 |
| Maintenance | Aging 652 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 92,972 / month, #13,410 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: ConsoleLicense :: OSI Approved :: BSD LicenseOperating System :: MacOS :: MacOS XOperating System :: Microsoft :: WindowsOperating System :: POSIXProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software Development :: Quality Assurance |
Evidence: dlint-0.16.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “python best practices linter”
- dlintDlint is a flake8 plugin that adds security-focused and best-practice…
- hadolint-coatlProvides a pip-installable hadolint binary wrapper that makes the…
- cfn-lintValidates AWS CloudFormation templates in YAML or JSON format against…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also flake8-pyi · flake8 · wemake-python-styleguide · flake8-mock-spec · flake8-eradicate · flake8-builtins · flake8-bandit · flake8-tidy-imports · flake8-print · flake8-functions