- Access private PyPI packages during dependency resolution
- Generate comprehensive security analysis including private dependencies
- Maintain complete visibility into your software supply chain
- Use package manager integrations to simplify scanning when authentication to private repositories is not part of standard manifest or settings files.
- Package manager integrations allow you to set custom repositories for each package ecosystem and the priority of each repository for scanning.
- Select User menu > Integrations from the left sidebar.
- Select Add next to the package manager configuration you want to add.
- Select Add Package Manager.
- Enter a Name for the integration.
- Choose an authentication type and complete the required fields.
- Optionally, under Advanced, select Propagate this package manager to all child namespaces to share this integration with child namespaces.
- Click Add Package Manager.
Test package manager integration
You can test the connection to a configured package manager to verify that Endor Labs can reach the repository. To test the connection:- Select User menu > Integrations from the left sidebar.
- Click Manage in the package manager configuration you want to customize.
- Click the vertical three dots of the package manager configured and select Test Connection.
The integration does not perform authentication or authorization checks on the package manager repository.
Edit package manager integration
You can edit an existing package manager integration to update the name, repository URL, or authentication credentials. To edit a package manager integration:- Select User menu > Integrations from the left sidebar.
- Click Manage next to the package manager you want to edit.
- Click the vertical three dots on the configured integration you want to edit and select Edit.
- You can modify the name, package manager URL, and credentials.
- Click Save Changes.
Private package manager integration for PyPI using API
Use endorctl to create a package manager resource through an API call and configure authentication for accessing private repositories during scans.The PyPI package manager URL typically ends with
/simple.usernamewith your package registry usernamexxxxwith your package registry passwordnamespacewith your namespace.
Fetch package manager using API
Run the following command to fetch the package manager using the UUID.Delete package manager using API
Run the following command to delete the package manager using the UUID.Poetry authentication behavior
Endor Labs matches each source declared in[[tool.poetry.source]] in your pyproject.toml file to a configured PyPI package manager integration by comparing normalized URLs (scheme, host, port, and path). When a source URL matches an integration with a complete username and password, Endor Labs passes the credentials to the poetry lock and poetry install commands during a scan.
Poetry derives the environment variable name for a source from its name. It converts the name to uppercase and replaces hyphens with underscores. Endor Labs follows the same convention, so a source named org-repo receives credentials as POETRY_HTTP_BASIC_ORG_REPO_USERNAME and POETRY_HTTP_BASIC_ORG_REPO_PASSWORD.
Endor Labs only supplies credentials for sources already declared in
pyproject.toml. It does not add or rewrite Poetry sources.Known limitations
- Existing credentials take precedence: If a source URL in
pyproject.tomlalready contains inline credentials, or if the correspondingPOETRY_HTTP_BASIC_*environment variables are already set, Endor Labs does not add or override them. - Shared credential keys: Poetry converts the source names to uppercase and replaces hyphens with underscores. Therefore, sources named
org-repoandorg_reporesolve to the same environment variable key. Endor Labs skips credential injection for that key, because one credential pair could otherwise authenticate requests to two different registry URLs. - Dotted source names: Poetry (version 2.4 and later) preserves dots in a source name when deriving its environment variable key. The earlier versions of Poetry replace dots with underscores. Because the correct key depends on the installed Poetry version, Endor Labs skips credential injection for source names that contain a dot.
- Basic authentication only: This behavior passes only username and password credentials matched by URL. Token-based authentication and mTLS certificates are not passed to Poetry commands.