Python Basics in Practical DevSecOps Labs: I/O, Virtual Environments, and pip
Python is used extensively in the Practical DevSecOps courses for scripting, automation, and security tooling. This article covers the essential Python skills: input/output, virtual environments, and package management with pip.
Table of Contents
Input and Output
Printing output
print("Hello, DevSecOps!")
Getting input
name = input("Enter your name: ")
print(f"Hello, {name}!")
Reading and writing files
# Writing to a file
with open("output.txt", "w") as f:
f.write("Scan results\n")
# Reading from a file
with open("output.txt", "r") as f:
content = f.read()
print(content)
Key data types
| Type | Example | Use Case |
|---|---|---|
str |
"hello" |
Text, command output |
int |
42 |
Counts, exit codes |
float |
3.14 |
Metrics, scores |
list |
[1, 2, 3] |
Ordered collections |
dict |
{"key": "value"} |
Structured data, JSON-like |
Virtual Environments
A virtual environment isolates Python packages for a specific project, preventing conflicts between dependencies.
Creating and activating
python3 -m venv env # create virtual environment
source env/bin/activate # activate it
Your prompt will change to show (env), indicating the environment is active.
Installing packages in the virtual environment
pip install django
Saving dependencies
pip freeze > requirements.txt # save all installed packages
Restoring dependencies
pip install -r requirements.txt # install from saved list
Deactivating
deactivate
Why use virtual environments?
| Benefit | Explanation |
|---|---|
| Isolation | Packages installed in one project don't affect others |
| Reproducibility | requirements.txt ensures the same packages everywhere |
| Clean system | No pollution of the system-wide Python installation |
Package Management with pip
pip is the Python package installer. It retrieves packages from the Python Package Index (PyPI).
Common commands
pip install package_name # install a package
pip install package_name==1.2.3 # install specific version
pip install package_name>=1.2.0 # install minimum version
pip list # list installed packages
pip show package_name # show package details
pip uninstall package_name # remove a package
pip search package_name # search PyPI
Version specifiers
| Specifier | Meaning |
|---|---|
==1.2.3 |
Exact version |
>=1.2.0 |
Minimum version |
<=1.5.0 |
Maximum version |
~=1.2.0 |
Compatible release (>=1.2.0, <1.3.0) |
Common Questions
| Question | Answer |
|---|---|
| Do I need to create a virtual environment for every project? | Yes, it's best practice to isolate each project's dependencies. |
What's the difference between pip and pip3? |
pip may point to Python 2 or 3 depending on your system. pip3 always uses Python 3. |
| Can I use pip outside a virtual environment? | Yes, but it's not recommended. Use --user flag to install packages in your home directory. |
| How do I check which Python version I'm using? | Run python3 --version. |
What does pip freeze vs pip list show? |
pip freeze shows packages in installable format (for requirements.txt). pip list shows a readable table. |
Wrap-Up
Python skills — input/output, virtual environments, and pip — form the foundation for scripting and automation in the Practical DevSecOps courses. Use virtual environments for isolation, requirements.txt for reproducibility, and pip for managing dependencies. These skills are used in AI Security, API Security, and DevSecOps Professional courses.