$npx skillfedfor your agent

safe-netrc

Safe netrc file parser

With conditionsPyPI InternetReleased Nov 202293.2K downloads / moGPL-2.0-or-laterPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — safe_netrc-1.0.1-py3-none-any.whl
v1.0.1 · released 2022-11-29 · Python >=3.7

Yes, if you need secure netrc parsing with strict permissions checks and environment-variable path override in a Python 3.7+ application. The package is stable and has no known vulnerabilities, but be aware it is abandoned and will not receive updates. Use it only if the current behavior meets your needs and you do not expect future maintenance.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.7 or later.
  • The netrc file must have restrictive permissions or the parser will reject it.
  • Low friction: pure Python wheel with no runtime dependencies.

License · maintenance · safety

GPL-2.0-or-later (copyleft) — GPL-2.0-or-later is a copyleft license requiring derivative works to be licensed under compatible terms. Any code that imports and modifies this package must be released under GPL-2.0-or-later or a compatible license.

last release 2022-11-29 (1354 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 93,230 downloads/mo, #13,397 on PyPI

Verify before relying

pip install safe-netrc

from safe_netrc import netrc
auth = netrc()
login, _, password = auth.authenticators('example.com')
  • Whether the abandoned status affects real-world use cases where netrc handling is stable and rarely needs updates.
  • Specific permission requirements the parser enforces on netrc files.
  • Whether permissions-check backport from Python 3.1 remains relevant given current Python version support (3.7+).
Same gist for agents: .md · .json

What it is and what it does

Safe-netrc is a drop-in replacement for Python's standard library netrc parser that adds stricter security and flexibility. It extends the netrc.netrc class to enforce file permissions checks and allows the netrc file path to be specified via the NETRC environment variable instead of always defaulting to ~/.netrc. The package backports permission validation that was added to the standard library in Python 3.1, ensuring consistent security behavior across Python versions.

The package is intended for applications that need to read authentication credentials from netrc files while maintaining strict security posture. It has no external runtime dependencies and installs as a pure Python wheel, making it lightweight and portable. However, the project is no longer actively maintained—the last release was in November 2022.

Use it for

  • Secure credential lookup in CLI tools or scripts that need to authenticate with remote services using netrc files.
  • Enforcing strict file permissions on credential files to prevent accidental exposure of passwords.
  • Allowing deployment scripts to override the default netrc location via NETRC environment variable for non-standard configurations.
  • Backporting secure netrc parsing to Python 3.7–3.9 environments where standard library behavior may differ.
  • Validating netrc file permissions in security-sensitive applications before attempting to read credentials.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need secure netrc parsing with strict permissions checks and environment-variable path override in a Python 3.7+ application.

The package is stable and has no known vulnerabilities, but be aware it is abandoned and will not receive updates. Use it only if the current behavior meets your needs and you do not expect future maintenance.

Install

safe-netrc on PyPI

Before you install

Low friction: pure Python wheel with no runtime dependencies. However, the package is abandoned—last release was 2022-11-29, over 1354 days ago. No active maintenance or security updates.

Requires Python 3.7 or later. The netrc file must have restrictive permissions or the parser will reject it.

License in practice

GPL-2.0-or-later is a copyleft license requiring derivative works to be licensed under compatible terms. Any code that imports and modifies this package must be released under GPL-2.0-or-later or a compatible license.

Quickstart

pip install safe-netrc

from safe_netrc import netrc
auth = netrc()
login, _, password = auth.authenticators('example.com')

Verify before relying

  • Whether the abandoned status affects real-world use cases where netrc handling is stable and rarely needs updates.
  • Specific permission requirements the parser enforces on netrc files.
  • Whether permissions-check backport from Python 3.1 remains relevant given current Python version support (3.7+).

Package facts

LicenseGPL-2.0-or-later copyleft
Python supportSupports the current Python release >=3.7
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceAbandoned 1,354 days since the last release
First released
Downloads93,230 / month, #13,397 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleLicense :: OSI Approved :: GNU General Public License v2 or later (GPLv2+)Operating System :: POSIXProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: InternetTopic :: Security

Evidence: safe_netrc-1.0.1-py3-none-any.whl

Tags

Capabilities
netrc file parsersecure credential storagenetrc permissions checkenvironment variable netrc pathsafe authentication filenetrc securitycredential file validation
Topics
credentialsauthenticationsecurity-hardening

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “netrc file parser”

  • safe-netrcProvides a safer subclass of Python's standard netrc parser that…
  • tinynetrcRead, parse, and write .netrc credential files with dictionary-style…
  • INIToolsINITools parses and manipulates INI-style configuration files through…

Give your agent the search over MCP, or paste the wish link into any chat.

More Internet packages

botocore Worth it
PyPI · Internet · released Aug 2026

Botocore provides low-level, data-driven access to Amazon Web Services APIs, serving as the foundation for the AWS CLI and boto3 libraries.

Install it if you need programmatic access to AWS services.

permissive licensepure Python · 3.10+
1.5Bdownloads / mo
aiobotocore Worth it
PyPI · Internet · released Aug 2026

Provides an async client for AWS services using botocore and aiohttp, allowing you to call AWS APIs asynchronously within asyncio-based applications.

Install it if you need to call AWS services from async Python code; it is the standard way to do so.

Apache-2.0pure Python · 3.10+
1.2Bdownloads / mo
pydantic Worth it
PyPI · Python Modules · released May 2026

Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.

MITpure Python · 3.9+
1.1Bdownloads / mo
filelock Worth it
PyPI · Libraries · released Aug 2026

Provides a platform-independent file locking mechanism to coordinate access to files across processes and threads.

MITpure Python · 3.10+
717.1Mdownloads / mo
fastapi Worth it
PyPI · Software Development · released Jul 2026

FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.

MITpure Python · 3.10+
568.6Mdownloads / mo
googleapis-common-protos Worth it
PyPI · Internet · released Aug 2026

Provides common Protocol Buffer message definitions used across Google Cloud APIs, enabling Python clients to interact with Google services.

Apache-2.0pure Python · 3.10+
513.7Mdownloads / mo

See also tinynetrc · tarsafe · robocorp-vault · requests-credssp · certifi-linux · pyspnego · keyring · path.py · keeper-secrets-manager-core · path