pyre-check
A performant type checker and security-focused static analyzer for Python
Decision gist · record as of 2026-08-14
Yes, if you need automated security scanning for Python. Pysa is actively maintained, has no known vulnerabilities, and scales to large codebases. Install it when your team wants continuous data-flow analysis without manual code review. Requires Python 3.9+, Pyrefly setup, and willingness to configure models for your specific threats.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; Pyrefly must successfully type-check your code before Pysa can analyze it.
- Medium install friction due to 12 runtime dependencies and platform-specific wheels (macOS ARM64, Linux x86_64).
- Active maintenance with recent release (8 days old) and ongoing repository activity supports reliability.
License · maintenance · safety
MIT (permissive) — MIT license is permissive; you can use, modify, and distribute Pysa with minimal restrictions, making it suitable for both open-source and commercial projects.
last release 2026-08-06 (8 days) · last repo commit 2026-08-13 · 18 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 238,446 downloads/mo, #8,937 on PyPI
Alternatives
Verify before relying
pip install pyre-check
pyrefly check
pyre analyze- Whether Pysa's taint models cover your specific security concerns or require custom model writing.
- Performance characteristics when analyzing your specific codebase size and complexity.
- Integration workflow with existing CI/CD pipelines beyond the GitHub Action mentioned.
What it is and what it does
Pysa is a security-focused static analyzer built on top of Pyrefly, Meta's Python type checker. It works by tracking how untrusted data (sources) flows through your code to dangerous operations (sinks), flagging paths that could lead to security vulnerabilities. The tool is designed to scale to large codebases and uses configurable models to identify sources and sinks relevant to your application.
You run Pysa after Pyrefly has successfully type-checked your code. It produces a report of potential security and privacy issues without executing your code. The tool ships as part of the pyre-check package and relies on a chain of dependencies including libcst for code parsing, click for CLI, and several typing utilities.
Use it for
- Scan a web application for user input reaching SQL queries or shell commands.
- Identify privacy violations where sensitive data flows to external APIs or logs.
- Integrate security scanning into CI/CD pipelines via the GitHub Action.
- Analyze large Python codebases for data exfiltration or injection vulnerabilities.
- Enforce security policies by configuring custom taint sources and sinks for your domain.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need automated security scanning for Python.
Pysa is actively maintained, has no known vulnerabilities, and scales to large codebases. Install it when your team wants continuous data-flow analysis without manual code review. Requires Python 3.9+, Pyrefly setup, and willingness to configure models for your specific threats.
Install
pyre-check on PyPI
Before you install
Medium install friction due to 12 runtime dependencies and platform-specific wheels (macOS ARM64, Linux x86_64). Active maintenance with recent release (8 days old) and ongoing repository activity supports reliability.
Requires Python 3.9 or later; Pyrefly must successfully type-check your code before Pysa can analyze it.
License in practice
MIT license is permissive; you can use, modify, and distribute Pysa with minimal restrictions, making it suitable for both open-source and commercial projects.
Quickstart
pip install pyre-check
pyrefly check
pyre analyze
Verify before relying
- Whether Pysa's taint models cover your specific security concerns or require custom model writing.
- Performance characteristics when analyzing your specific codebase size and complexity.
- Integration workflow with existing CI/CD pipelines beyond the GitHub Action mentioned.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 12 packagesclickdataclasses-jsonlibcstpsutilpyre-extensionstabulatetestslidetyping-extensionstyping-inspecttomlitomli-wpyrefly |
| Maintenance | Actively maintained 8 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 238,446 / month, #8,937 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: MacOSOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Topic :: Software DevelopmentTyping :: Typed |
Evidence: pyre_check-0.10.0-py3-none-macosx_11_0_arm64.whl; pyre_check-0.10.0-py3-none-manylinux1_x86_64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “data flow taint analysis”
- pyre-checkPysa is a static analysis tool that tracks data flows through Python…
- FlowIOFlowIO reads and writes Flow Cytometry Standard (FCS) files, the…
- collate-sqllineageAnalyzes SQL statements to extract source and target tables,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also pyrefly · safety · flawfinder · zaproxy · pylint · dodgy · cisco-ai-mcp-scanner · uv-secure · zizmor · pyre-extensions