ambolt

CRA Index / PyPI / iniconfig

iniconfig and the Cyber Resilience Act

4 of 4 readable security signals are in place for iniconfig 2.3.0 (PyPI). Data checked 2026-10-05.

iniconfig 2.3.04 of 4 signals
Signals from public data, not a compliance assessment. A missing signal can mean the project keeps it elsewhere.

iniconfig 2.3.0 is the current default version of this PyPI package, published on 2025-10-18. The registry lists 10 versions in total and the licence declared is MIT. The source repository is pytest-dev/iniconfig with 62 stars.

There is no OpenSSF Scorecard result for this package, so the repository signals (maintenance, security policy, code review, workflow hygiene, testing) are unknown rather than missing.

As of 2026-10-05, deps.dev lists no known advisories for this version. That is a snapshot and not a promise: new advisories can be published at any time.

If you ship a product that includes iniconfig, the Cyber Resilience Act expects you to know which components you ship, to follow their vulnerabilities and to exercise due diligence on third-party components (Annex I, Part II and Article 13). In practice: list iniconfig 2.3.0 in your SBOM with its package URL pkg:pypi/[email protected], watch for new advisories, and keep the upstream security contact in your vulnerability handling process.

Put the badge in your README

CRA signals for iniconfig

Check your own project

Run the repository check on pytest-dev/iniconfig, or check your own SBOM and create the licence notices.

More in the index

typing-inspection, zipp, pyasn1, referencing, aiohappyeyeballs, propcache · all PyPI packages

Sources and method

Package and version facts, licences, advisories and provenance: deps.dev (generated data under CC BY 4.0; advisories from OSV). Repository signals: the OpenSSF Scorecard. We read them on 2026-10-05 and show them without scoring the people behind a project. The nine signals are our selection; unknown means the data is not published.

Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.