$npx skillfedfor your agent

tarsafe

A safe subclass of the TarFile class for interacting with tar files. Can be used as a direct drop-in replacement for safe usage of extractall()

With conditionsPyPI SecurityReleased Mar 2023396.8K downloads / moMIT LicensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — tarsafe-0.0.5-py3-none-any.whl
v0.0.5 · released 2023-03-21 · Python >=3.6

Yes, if you extract tar files from untrusted sources or need to harden an existing tarfile-based workflow. The zero-dependency design and drop-in API make adoption straightforward. Verify that it addresses your specific threat model before relying on it for critical security boundaries.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low friction—pure Python wheel with no runtime dependencies.
  • Maintenance is active with a recent commit on 2026-08-13, though the latest release is from 2023-03-21.

License · maintenance · safety

MIT License (permissive) — MIT License permits free use, modification, and distribution with minimal restrictions, suitable for both open-source and commercial projects.

last release 2023-03-21 (1242 days) · last repo commit 2026-08-13 · 24 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 396,782 downloads/mo, #6,969 on PyPI

Verify before relying

pip install tarsafe

from tarsafe import TarSafe

with TarSafe.open("example.tar", "r") as tar:
    tar.extractall()
  • What specific path traversal attack vectors does extractall() address beyond the 6 year old security bug mentioned?
  • Does the package handle symlink attacks or other tar-specific security issues beyond directory traversal?
Same gist for agents: .md · .json

What it is and what it does

Tarsafe is a security-focused wrapper around Python's standard tarfile module designed to address a long-standing vulnerability in the extractall() method. The standard library's tarfile.extractall() can be exploited to write files outside the intended extraction directory through crafted tar archives. Tarsafe provides a TarSafe class that acts as a drop-in replacement, sanitizing extraction paths to prevent these attacks.

The package requires Python 3.6 or later and has no external runtime dependencies, making it lightweight to integrate into existing projects. It maintains the same API as the standard tarfile module, so switching from tarfile.TarFile to TarSafe.open() typically requires only a single line change. The project is actively maintained with recent updates.

Use it for

  • Safely extract user-uploaded tar archives in web applications without risk of directory traversal attacks.
  • Process untrusted tar files in automated build or deployment pipelines where path validation is critical.
  • Replace tarfile in existing codebases to harden against tar-based exploits with minimal refactoring.
  • Handle tar archives in security-sensitive contexts such as package managers or container image extraction.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you extract tar files from untrusted sources or need to harden an existing tarfile-based workflow.

The zero-dependency design and drop-in API make adoption straightforward. Verify that it addresses your specific threat model before relying on it for critical security boundaries.

Install

tarsafe on PyPI

Before you install

Low friction—pure Python wheel with no runtime dependencies. Maintenance is active with a recent commit on 2026-08-13, though the latest release is from 2023-03-21.

License in practice

MIT License permits free use, modification, and distribution with minimal restrictions, suitable for both open-source and commercial projects.

Quickstart

pip install tarsafe

from tarsafe import TarSafe

with TarSafe.open("example.tar", "r") as tar:
    tar.extractall()

Verify before relying

  • What specific path traversal attack vectors does extractall() address beyond the 6 year old security bug mentioned?
  • Does the package handle symlink attacks or other tar-specific security issues beyond directory traversal?

Package facts

LicenseMIT License permissive
Python supportSupports the current Python release >=3.6
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 1,242 days since the last release
Last repo commit
First released
Downloads396,782 / month, #6,969 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: tarsafe-0.0.5-py3-none-any.whl

Tags

Capabilities
tar extraction securitysafe tarfile extractiontar archive vulnerabilitytarfile security wrapperpath traversal prevention
Topics
path-traversal-defensearchive-security

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “tar extraction security”

  • tarsafeTarsafe wraps Python's tarfile module to prevent path traversal…
  • tzsttzst creates and extracts tar archives compressed with Zstandard,…
  • devpi-commonProvides shared utility functions for devpi-server and devpi-client,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also backports.tarfile · securetar · advocate · pyunpack · fastar · tzst · rpmfile · unix-ar · devpi-common · safe-netrc