# \#security

**URL:** https://discourse.julialang.org/tag/security/109.md

[Latest](https://discourse.julialang.org/latest.md) · [Categories](https://discourse.julialang.org/categories.md) · [Tags](https://discourse.julialang.org/tags.md)

---

## [Advice for local sandboxing](https://discourse.julialang.org/t/advice-for-local-sandboxing/136454)

<div class="topic-metadata">

**Author:** [@Benny](https://discourse.julialang.org/u/Benny)\
**Replies:** 9\
**Last updated:** [July 9, 2026, 2:42am UTC](https://discourse.julialang.org/t/advice-for-local-sandboxing/136454 "2026-07-09T02:42:19Z")

</div>

The TeamPCP attacks this year involving Github Actions, Trivy, npm (CanisterWorm), CheckMarx, Docker Hub, PyPI, LiteLLM, Telnyx, etc. has made me reconsider the security gamble I take whenever I download software. Despit…

---

## [Secure coding in Julia?](https://discourse.julialang.org/t/secure-coding-in-julia/115972)

<div class="topic-metadata">

**Author:** [@gdalle](https://discourse.julialang.org/u/gdalle)\
**Replies:** 19\
**Last updated:** [June 3, 2026, 9:36pm UTC](https://discourse.julialang.org/t/secure-coding-in-julia/115972 "2026-06-03T21:36:22Z")

</div>

Hi all, Someone asked a question on the ModernJuliaWorkflows repo, and I have no clue how to answer. They are looking for tools related to SAST (Static Analysis Security Testing) and SCA (Software Composition Analysis) …

---

## [LiteLLM PyPI compromised and Julia resilience to supply-chain attack](https://discourse.julialang.org/t/litellm-pypi-compromised-and-julia-resilience-to-supply-chain-attack/136364)

<div class="topic-metadata">

**Author:** [@fdekerme](https://discourse.julialang.org/u/fdekerme)\
**Replies:** 4\
**Last updated:** [March 25, 2026, 8:05pm UTC](https://discourse.julialang.org/t/litellm-pypi-compromised-and-julia-resilience-to-supply-chain-attack/136364 "2026-03-25T20:05:19Z")

</div>

Hi everyone, It was recently discovered that the litellm package (v1.82.8) was compromised with a malicious .pth file that could steal SSH keys, environment variables, and other credentials without requiring an explicit…

---

## [Launching the Julia Security Working Group](https://discourse.julialang.org/t/launching-the-julia-security-working-group/134116)

<div class="topic-metadata">

**Author:** [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Replies:** 1\
**Last updated:** [December 5, 2025, 2:17pm UTC](https://discourse.julialang.org/t/launching-the-julia-security-working-group/134116 "2025-12-05T14:17:03Z")

</div>

We’ve just published a new blog post announcing a new community working group: Julia Security! In addition to announcing the working group and a kickoff meeting, the blog post describes some of the many efforts over t…

---

## [Trusted libraries/packages - "package managers are evil"](https://discourse.julialang.org/t/trusted-libraries-packages-package-managers-are-evil/132320)

<div class="topic-metadata">

**Author:** [@Palli](https://discourse.julialang.org/u/Palli)\
**Replies:** 12\
**Last updated:** [September 18, 2025, 8:23am UTC](https://discourse.julialang.org/t/trusted-libraries-packages-package-managers-are-evil/132320 "2025-09-18T08:23:55Z")

</div>

We implicitly trust all packages we use, for security (and bugs). I realized maybe we shouldn’t and packages should be untrusted by default. How could you do it? I see two ways. you could do: using trusted \<package\> …

---

## [Security review](https://discourse.julialang.org/t/security-review/132041)

<div class="topic-metadata">

**Author:** [@amrods](https://discourse.julialang.org/u/amrods)\
**Replies:** 9\
**Last updated:** [September 2, 2025, 5:48pm UTC](https://discourse.julialang.org/t/security-review/132041 "2025-09-02T17:48:45Z")

</div>

I convinced my organization to give Julia a try. I am now responsible for setting up a process to review and approve code libraries prior to inclusion to a local software repository. I am to perform vulnerability scanni…

---

## [Finding package that requires admin permission to install](https://discourse.julialang.org/t/finding-package-that-requires-admin-permission-to-install/131758)

<div class="topic-metadata">

**Author:** [@juliohm](https://discourse.julialang.org/u/juliohm)\
**Replies:** 3\
**Last updated:** [August 21, 2025, 8:01pm UTC](https://discourse.julialang.org/t/finding-package-that-requires-admin-permission-to-install/131758 "2025-08-21T20:01:51Z")

</div>

I gave a short-course this last weekend and the participants reported a pop-up window asking for admin permission while installing GeoStats.jl on Windows machines in their lab. How can I identify the indirect dependenc…

---

## [Security Advisory: HTTP.jl, URIs.jl, Registrator.jl, GitForge.jl, and GitHub.jl](https://discourse.julialang.org/t/security-advisory-http-jl-uris-jl-registrator-jl-gitforge-jl-and-github-jl/130189)

<div class="topic-metadata">

**Author:** [@avik](https://discourse.julialang.org/u/avik)\
**Replies:** 2\
**Last updated:** [June 26, 2025, 7:49pm UTC](https://discourse.julialang.org/t/security-advisory-http-jl-uris-jl-registrator-jl-gitforge-jl-and-github-jl/130189 "2025-06-26T19:49:42Z")

</div>

Security vulnerabilities have been reported in a few Julia packages. We recommend all users upgrade to the latest version of these packages as soon as possible. Each vulnerability has been assigned a CVE and published as…

---

## [Security Advisory: HTMLSanitizer.jl](https://discourse.julialang.org/t/security-advisory-htmlsanitizer-jl/130136)

<div class="topic-metadata">

**Author:** [@avik](https://discourse.julialang.org/u/avik)\
**Replies:** 0\
**Last updated:** [June 23, 2025, 2:29pm UTC](https://discourse.julialang.org/t/security-advisory-htmlsanitizer-jl/130136 "2025-06-23T14:29:13Z")

</div>

There is a known vulnerability in the HTMLSanitzer.jl package in all versions below v0.2.1. We recommend all users upgrade to version v0.2.1 as soon as possible. More details here: Possible XSS in HTMLSanitizer when usi…

---

## [\[ANN\] B7nSecretsManagerUnoffClient.jl - An unofficial Julia client for Bitwarden Secrets Manager](https://discourse.julialang.org/t/ann-b7nsecretsmanagerunoffclient-jl-an-unofficial-julia-client-for-bitwarden-secrets-manager/126427)

<div class="topic-metadata">

**Author:** [@scelles](https://discourse.julialang.org/u/scelles)\
**Replies:** 0\
**Last updated:** [February 28, 2025, 4:14pm UTC](https://discourse.julialang.org/t/ann-b7nsecretsmanagerunoffclient-jl-an-unofficial-julia-client-for-bitwarden-secrets-manager/126427 "2025-02-28T16:14:12Z")

</div>

Hello Julia Community! I’m excited to share my work on BitwardenSecretsManagerUnofficialClient.jl, an unofficial Julia client for Bitwarden Secrets Manager. What is Bitwarden Secrets Manager? For those unfamiliar, Bitw…

---

## [Accessing the macOS Keychain from Julia](https://discourse.julialang.org/t/accessing-the-macos-keychain-from-julia/119693)

<div class="topic-metadata">

**Author:** [@e3c6](https://discourse.julialang.org/u/e3c6)\
**Replies:** 1\
**Last updated:** [September 22, 2024, 10:21am UTC](https://discourse.julialang.org/t/accessing-the-macos-keychain-from-julia/119693 "2024-09-22T10:21:08Z")

</div>

How can one access the macOS Keychain from Julia ? To store or retrieve passwords.

---

## [PSA: backdoor in xz-utils and relevance for the Julia ecosystem](https://discourse.julialang.org/t/psa-backdoor-in-xz-utils-and-relevance-for-the-julia-ecosystem/112328)

<div class="topic-metadata">

**Author:** [@giordano](https://discourse.julialang.org/u/giordano)\
**Replies:** 2\
**Last updated:** [April 2, 2024, 8:18pm UTC](https://discourse.julialang.org/t/psa-backdoor-in-xz-utils-and-relevance-for-the-julia-ecosystem/112328 "2024-04-02T20:18:26Z")

</div>

Statement of the problem A thread in oss-security mailing list reported that the XZ Utils project was affected by a backdoor: one of the current maintainers of the project appeared to have injected malicious code, includ…

---

## [Malicious code in XZ\_jll.jl (v5.6.1+0) ; it could pose a problem?](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311)

<div class="topic-metadata">

**Author:** [@ImreSamu](https://discourse.julialang.org/u/ImreSamu)\
**Replies:** 3\
**Last updated:** [March 30, 2024, 12:41pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311 "2024-03-30T12:41:02Z")

</div>

Based on my examination of the package https://juliahub.com/ui/Packages/General/XZ\_jll - XZ\_jll.jl (v5.6.1+0) it appears to be connected to a security issue detailed here: https://www.phoronix.com/news/XZ-CVE-2024-3094 …

---

## [Safety Download files](https://discourse.julialang.org/t/safety-download-files/108233)

<div class="topic-metadata">

**Author:** [@CeterisPartybus](https://discourse.julialang.org/u/CeterisPartybus)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 4:19pm UTC](https://discourse.julialang.org/t/safety-download-files/108233 "2024-01-02T16:19:41Z")

</div>

This might be a stupid question as I am not a network/security guy. I am thinking about implementing a feature in a package I develop that downloads a file from an external server. Should safety be a concern here? Spec…

---

## [Vulnerability analysis of the julia dependency library](https://discourse.julialang.org/t/vulnerability-analysis-of-the-julia-dependency-library/102039)

<div class="topic-metadata">

**Author:** [@zhenyaylitin](https://discourse.julialang.org/u/zhenyaylitin)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 7:49pm UTC](https://discourse.julialang.org/t/vulnerability-analysis-of-the-julia-dependency-library/102039 "2023-07-24T19:49:51Z")

</div>

Colleagues, good afternoon! Please tell me if there are currently analyzers of libraries of their dependencies for the julia language. For example, python has pip-audit or safity, for the R language there is oysteR. May…

---

## [Is startup.jl an acceptable place to store credentials for interactive scripts?](https://discourse.julialang.org/t/is-startup-jl-an-acceptable-place-to-store-credentials-for-interactive-scripts/98343)

<div class="topic-metadata">

**Author:** [@mkjohnson](https://discourse.julialang.org/u/mkjohnson)\
**Replies:** 6\
**Last updated:** [May 5, 2023, 5:56am UTC](https://discourse.julialang.org/t/is-startup-jl-an-acceptable-place-to-store-credentials-for-interactive-scripts/98343 "2023-05-05T05:56:28Z")

</div>

Hi ya’ll! I had a question about using startup.jl in the home directory (not the project) to store credentials as environment variables. I come from an R background, and I’m used to storing credentials in the .Renviron …

---

## [How to update Julia in ssh clusters](https://discourse.julialang.org/t/how-to-update-julia-in-ssh-clusters/88351)

<div class="topic-metadata">

**Author:** [@greivin](https://discourse.julialang.org/u/greivin)\
**Replies:** 11\
**Last updated:** [October 6, 2022, 11:35pm UTC](https://discourse.julialang.org/t/how-to-update-julia-in-ssh-clusters/88351 "2022-10-06T23:35:39Z")

</div>

I’m working as a PhD student in a lab with ssh clusters, I have the access to connect to each one of them (there’s no queue system, as it is a small lab, hence, as long as someone is not using a lot of cores in each comp…

---

## [Q: automatically updating/detecting missed JLL packages updates](https://discourse.julialang.org/t/q-automatically-updating-detecting-missed-jll-packages-updates/81413)

<div class="topic-metadata">

**Author:** [@ImreSamu](https://discourse.julialang.org/u/ImreSamu)\
**Replies:** 4\
**Last updated:** [May 24, 2022, 2:21pm UTC](https://discourse.julialang.org/t/q-automatically-updating-detecting-missed-jll-packages-updates/81413 "2022-05-24T14:21:11Z")

</div>

context: Some JLL packages are not updated to the latest version so important (security) patches not used. hard to find these packages in the local environments. example: LibPQ\_jll ( PostgreSQL client) - based on v…

---

## [Known Security Vulnerabilities](https://discourse.julialang.org/t/known-security-vulnerabilities/67828)

<div class="topic-metadata">

**Author:** [@hmray2025](https://discourse.julialang.org/u/hmray2025)\
**Replies:** 8\
**Last updated:** [April 25, 2022, 8:21pm UTC](https://discourse.julialang.org/t/known-security-vulnerabilities/67828 "2022-04-25T20:21:55Z")

</div>

Is there any comprehensive list of known security vulnerabilities or associated strengths with Julia? I’m working with the DoD to enable ML applications for data science and am hoping to use Julia in our implementation. …

---

## [Log4jl Julia package security concern](https://discourse.julialang.org/t/log4jl-julia-package-security-concern/73258)

<div class="topic-metadata">

**Author:** [@Sascha\_McDonald](https://discourse.julialang.org/u/Sascha_McDonald)\
**Replies:** 8\
**Last updated:** [December 19, 2021, 1:24pm UTC](https://discourse.julialang.org/t/log4jl-julia-package-security-concern/73258 "2021-12-19T13:24:22Z")

</div>

Hey Guys, “Log4jl has similar architecture as Apache Log4j 2 framework.” Sorry if this is already been addressed. However, I haven’t been able to find any sign of a security statement from the community about the follo…

---

## [How to find token for Pluto running on a remote server?](https://discourse.julialang.org/t/how-to-find-token-for-pluto-running-on-a-remote-server/62056)

<div class="topic-metadata">

**Author:** [@yingqiuz](https://discourse.julialang.org/u/yingqiuz)\
**Replies:** 5\
**Last updated:** [May 30, 2021, 7:19pm UTC](https://discourse.julialang.org/t/how-to-find-token-for-pluto-running-on-a-remote-server/62056 "2021-05-30T19:19:30Z")

</div>

Hi I am trying to run Pluto.run(port=1235) on a remote server. And the output showed Go to http://localhost:1235/?secret=gMCHSxJl in your browser to start writing ~ have fun! After I built the tunnel and tried to conn…

---

## [Fuzzing Julia functions (for security hardening)](https://discourse.julialang.org/t/fuzzing-julia-functions-for-security-hardening/58950)

<div class="topic-metadata">

**Author:** [@Krastanov](https://discourse.julialang.org/u/Krastanov)\
**Replies:** 3\
**Last updated:** [April 10, 2021, 8:29pm UTC](https://discourse.julialang.org/t/fuzzing-julia-functions-for-security-hardening/58950 "2021-04-10T20:29:56Z")

</div>

This came up when I was asking whether Meta.parse is safe to use. While the function itself is supposed to be safe in principle, it has not been hardened (audited for security bugs). Fuzzing seems like one of the standar…

---

## [How to Best Store and Access Credentials in Julia?](https://discourse.julialang.org/t/how-to-best-store-and-access-credentials-in-julia/54997)

<div class="topic-metadata">

**Author:** [@TheCedarPrince](https://discourse.julialang.org/u/TheCedarPrince)\
**Replies:** 13\
**Last updated:** [February 11, 2021, 12:30pm UTC](https://discourse.julialang.org/t/how-to-best-store-and-access-credentials-in-julia/54997 "2021-02-11T12:30:09Z")

</div>

Hi all, I was recently stumped by something: Suppose I have some credentials I need to store to access a SQL DB. How should I best store these credentials for Julia to easily access? My current pattern is to use a com…

---

## [Pkg: attack vectors](https://discourse.julialang.org/t/pkg-attack-vectors/18340)

<div class="topic-metadata">

**Author:** [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Replies:** 25\
**Last updated:** [September 17, 2020, 9:19am UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340 "2020-09-17T09:19:23Z")

</div>

Pkg ecosystem: Learning from other's mistakes has gotten a bit long and wandering, as these discussions tend to. I’d like to have a very focused thread about attack vectors against the security of the package ecosystem. …

---

## [Enabling 2FA on major Github orgs](https://discourse.julialang.org/t/enabling-2fa-on-major-github-orgs/31957)

<div class="topic-metadata">

**Author:** [@viralbshah](https://discourse.julialang.org/u/viralbshah)\
**Replies:** 12\
**Last updated:** [April 10, 2020, 7:29pm UTC](https://discourse.julialang.org/t/enabling-2fa-on-major-github-orgs/31957 "2020-04-10T19:29:01Z")

</div>

I think it would be great for major orgs to turn on 2FA for all org members as general security hygiene. We did this on JuliaLang a while ago, and I enabled it on JuliaPackaging today. I am sure some orgs already do thi…

---

## [Security scanning of Julia code](https://discourse.julialang.org/t/security-scanning-of-julia-code/24253)

<div class="topic-metadata">

**Author:** [@bluesmoon](https://discourse.julialang.org/u/bluesmoon)\
**Replies:** 5\
**Last updated:** [May 16, 2019, 3:51pm UTC](https://discourse.julialang.org/t/security-scanning-of-julia-code/24253 "2019-05-16T15:51:29Z")

</div>

Hi all, I was wondering what other people do to keep track of scanning Julia code for security vulnerabilities and if any vulnerabilities get reported to CVE. Thanks, Philip

---

## [JuliaPro file integrity](https://discourse.julialang.org/t/juliapro-file-integrity/12701)

<div class="topic-metadata">

**Author:** [@dnk8n](https://discourse.julialang.org/u/dnk8n)\
**Replies:** 2\
**Last updated:** [July 30, 2018, 5:23am UTC](https://discourse.julialang.org/t/juliapro-file-integrity/12701 "2018-07-30T05:23:36Z")

</div>

Hi, I have been struggling to download Julia for a few days now (Slow South African internet connections!). The link seems to expire mid download. Eventually I got a full download (potentially). I would like to verify i…

---

## [Parallel julia - TCP ports and security](https://discourse.julialang.org/t/parallel-julia-tcp-ports-and-security/3618)

<div class="topic-metadata">

**Author:** [@anon94023334](https://discourse.julialang.org/u/anon94023334)\
**Replies:** 2\
**Last updated:** [May 9, 2017, 8:58pm UTC](https://discourse.julialang.org/t/parallel-julia-tcp-ports-and-security/3618 "2017-05-09T20:58:48Z")

</div>

I noticed that Julia opens up TCP port 9100 when addprocs() is used. Is there a description of how that port is used, along with the security controls surrounding its use (and of the network communication in general)? (M…
