{
  "schema": "tesign-radar/item/1",
  "generated_at": "2026-09-22T07:26:19.753Z",
  "lang": "ko",
  "slug": "package-doctor",
  "url": "https://tesign.com/item/package-doctor/",
  "alternates": {
    "ko": {
      "html": "https://tesign.com/item/package-doctor/",
      "json": "https://tesign.com/item/package-doctor/index.json",
      "markdown": "https://tesign.com/item/package-doctor/index.md"
    },
    "en": {
      "html": "https://tesign.com/en/item/package-doctor/",
      "json": "https://tesign.com/en/item/package-doctor/index.json",
      "markdown": "https://tesign.com/en/item/package-doctor/index.md"
    }
  },
  "name": "package-doctor",
  "use_label": "취약 패키지 점검",
  "one_liner": "파이썬 의존성 중 실제로 뚫리고 있는 것과 고칠 사람이 없는 것을 가려내는 점검 도구.",
  "text": {
    "why": "의존성 하나에 취약점 경고가 수십 개씩 쌓이면 뭐부터 봐야 할지 알기 어렵다. package-doctor는 CISA의 실제 악용 목록과 EPSS 점수로 순서를 매기고, 신뢰 경계(외부 입력을 다루는 자리)에 있으면서 고칠 사람도 없는 패키지만 \"교체\" 대상으로 올린다. 나머지는 \"조용함\"으로 넘긴다.",
    "take": "취약점 수를 그냥 나열하지 않고 \"지금 뚫려 있는가·고칠 사람이 있는가\" 두 축으로 걸러 낸다는 점이 다른 스캐너와 갈린다.",
    "build": [
      "파이썬으로 만들었고 pip install package-doctor로 받는다. uv.lock·poetry.lock·Pipfile.lock·requirements.txt 등을 읽고, 약 1,500개 패키지를 사람이 직접 검토한 지도를 근거로 신뢰 경계 여부를 판단한다. Claude Code 훅으로 쓰면 에이전트가 새 패키지를 설치하려 할 때 지어낸 이름·최근 등록·위험 패키지를 막는다. CI·pre-commit·SARIF 출력도 지원한다."
    ],
    "who": [
      {
        "role": "파이썬 프로젝트를 운영하는 개발자, AI 코딩 에이전트가 마음대로 패키지를 넣는 걸 막고 싶은 팀.",
        "situation": null
      }
    ],
    "start": [
      {
        "command": false,
        "text": "pip install package-doctor로 설치하고 package-doctor scan을 실행한다."
      }
    ],
    "caveat": [
      "신뢰 경계 판단은 사람이 검토한 약 1,500개 패키지 지도에 의존하므로, 그 목록에 없는 패키지는 \"확인 안 됨\"으로 남는다. 파이썬 프로젝트 전용이다."
    ]
  },
  "cta": {
    "type": "install",
    "label": "INSTALL",
    "url": "https://pypi.org/project/package-doctor"
  },
  "ready": "install",
  "categories": [
    "security",
    "dev-tools"
  ],
  "categories_confirmed": true,
  "tags": [
    "보안 점검",
    "파이썬",
    "의존성",
    "claude code 훅"
  ],
  "platform": [
    "cli"
  ],
  "license": {
    "spdx": "MIT",
    "scope": "permissive",
    "scope_text": "상업 이용·수정·재배포 가능. 저작권 고지는 유지.",
    "url": "https://spdx.org/licenses/MIT.html",
    "note": null,
    "open_source": true
  },
  "language": "Python",
  "source_urls": {
    "canonical": "https://pypi.org/project/package-doctor",
    "github": "https://github.com/binuka200/package-doctor",
    "huggingface": null,
    "app_store": null,
    "sightings": [
      {
        "source": "showhn",
        "url": "https://github.com/binuka200/package-doctor",
        "posted_at": "2026-09-19T00:27:26.000Z",
        "hn_url": "https://news.ycombinator.com/item?id=49762076"
      }
    ]
  },
  "numbers": {
    "as_of": "2026-09-22T03:00:00.000Z",
    "stars": 8,
    "stars_unit": "GitHub stars",
    "stars_checked_at": "2026-09-19T03:09:08.818Z",
    "stars_observed_since_check": 0,
    "star_delta_24h": null,
    "star_delta_7d": null,
    "star_delta_30d": null,
    "star_delta_unit": "GitHub stars gained in the window, GH Archive events summed to as_of",
    "spark_14d": [
      null,
      null,
      null,
      null,
      null,
      null,
      null,
      null,
      null,
      null,
      null,
      null,
      null,
      null
    ],
    "hf_likes": null,
    "hf_likes_observed_at": null,
    "hn_points": 4,
    "hn_points_observed_at": "2026-09-22T01:35:29.153Z",
    "store": null,
    "method": "별 총합 = GitHub에서 마지막으로 확인한 값(stars_checked_at) + 그 뒤 GH Archive에서 관측한 증가. 24h·7d·30d 증가는 GH Archive 시간별 이벤트를 기준 시각(as_of)까지 합한 값. 우리 점수는 없습니다."
  },
  "ranks": null,
  "activity": {
    "pushed_at": "2026-09-16T22:00:09.000Z",
    "owner_type": null,
    "open_issues": null,
    "contributors": null,
    "releases_count": null,
    "latest_release": null,
    "checked_at": null,
    "core_checked_at": "2026-09-19T03:09:08.818Z"
  },
  "signals": [
    {
      "kind": "new",
      "label": "신규",
      "value": "생성 1h 만에 포착"
    }
  ],
  "images": {
    "og": "https://tesign.com/img/package-doctor-888d02a454.png",
    "cover": "https://tesign.com/img/package-doctor-888d02a454.png",
    "cover_width": 3696,
    "cover_height": 2198,
    "gallery": [
      "https://tesign.com/img/package-doctor-888d02a454.png",
      "https://tesign.com/img/package-doctor-dff2bc33aa.png"
    ],
    "alt": "package-doctor scan 실행 결과. FIX TODAY로 pillow·litellm이 뜨고, 아래에 교체·완화·업그레이드·조용함으로 나뉜 패키지 목록이 터미널에 있다.",
    "tier": 2
  },
  "dates": {
    "first_seen_at": "2026-09-19T02:09:06.883Z",
    "source_created_at": "2026-09-19T00:27:26.000Z",
    "discovery_hours": 1.6946897222222221,
    "launch_signal_at": "2026-09-19T00:27:26.000Z",
    "kept_at": "2026-09-22T05:53:16.173Z",
    "first_published_at": "2026-09-22T05:53:16.495Z",
    "updated_at": "2026-09-22T05:53:16.435Z",
    "ingestion_mode": "live"
  },
  "notes": [
    "이 파일은 tesign.com 항목 페이지와 같은 빌드에서 같은 데이터로 만들어졌습니다. 소개 글은 편집자가 쓴 것이고, 숫자는 저장된 관측값입니다.",
    "JSON의 null은 관측하지 않았다는 뜻입니다 — 0이 아닙니다. 마크다운에서는 [확인 필요]로 적습니다.",
    "별 총합 = GitHub에서 마지막으로 확인한 값(stars_checked_at) + 그 뒤 GH Archive에서 관측한 증가. 24h·7d·30d 증가는 GH Archive 시간별 이벤트를 기준 시각(as_of)까지 합한 값. 우리 점수는 없습니다.",
    "요약이며 법적 조언이 아닙니다."
  ]
}
