CRA Index / PyPI / trove-classifiers
trove-classifiers and the Cyber Resilience Act
4 of 9 readable security signals are in place for trove-classifiers 2026.9.21.13 (PyPI). Data checked 2026-10-05.
- passNo known vulnerabilities in the latest version: none listed (Annex I, Part II: address and remediate vulnerabilities without delay)
- passNot deprecated: not marked as deprecated (support period and updates)
- missingActively maintained: Scorecard Maintained 1/10 (security updates for the whole support period)
- missingSecurity policy: Scorecard Security-Policy 0/10 (Annex I, Part II: coordinated vulnerability disclosure policy and contact address)
- missingLicence declared: non-standard (component documentation and licence notices)
- passCode review before merge: Scorecard Code-Review 10/10 (secure development process (Annex VII, development and vulnerability handling processes))
- missingCI workflow hygiene: Dangerous-Workflow 10, Token-Permissions 0 (integrity of the build and update chain)
- passSigned releases or provenance: build provenance or attestations published (Annex I, Part II: secure distribution of updates)
- missingAutomated security testing: SAST 0, Fuzzing 0 (Annex I, Part II: effective and regular tests and reviews)
trove-classifiers 2026.9.21.13 is the current default version of this PyPI package, published on 2026-09-21. The registry lists 128 versions in total and the licence declared is non-standard. The source repository is pypa/trove-classifiers with 191 stars.
The OpenSSF Scorecard for the repository was last computed on 2026-08-24 and gives an overall 4.8/10. Signals that are not in place today: actively maintained; security policy; licence declared; ci workflow hygiene; automated security testing.
As of 2026-10-05, deps.dev lists no known advisories for this version. That is a snapshot and not a promise: new advisories can be published at any time.
If you ship a product that includes trove-classifiers, the Cyber Resilience Act expects you to know which components you ship, to follow their vulnerabilities and to exercise due diligence on third-party components (Annex I, Part II and Article 13). In practice: list trove-classifiers 2026.9.21.13 in your SBOM with its package URL pkg:pypi/[email protected], watch for new advisories, and note that you have no published security contact upstream, so plan how you would report a problem. With several signals missing, consider whether a better-maintained alternative exists.
Put the badge in your README
Check your own project
Run the repository check on pypa/trove-classifiers, or check your own SBOM and create the licence notices.
More in the index
s3transfer, pathspec, aiosignal, sniffio, importlib-metadata, frozenlist · all PyPI packages
Sources and method
Package and version facts, licences, advisories and provenance: deps.dev (generated data under CC BY 4.0; advisories from OSV). Repository signals: the OpenSSF Scorecard. We read them on 2026-10-05 and show them without scoring the people behind a project. The nine signals are our selection; every signal could be read for this package.
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.