Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 29-Oct-2024 11:03:38 JST
-
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 29-Oct-2024 11:03:38 JST Haelwenn /элвэн/ :triskell: @GNUxeava Best of python is how pip and PyPI is a complete disaster in terms of security.
- Random binaries? Weee! Those can even be put into lockfiles, good luck vetting those.
- setup.py means pip will execute code, even for just downloads