Skip to content

Comment on PyPI has completed its first security auditparent

Comments

Yes, because you could in theory run `pip install`, then manually read through every file you've just downloaded, then run `python myapp.py`.

This security model is utter nonsense because no one does this.

Replace "manually read through every file" with "run your security code scanner against every file" and it becomes less nonsense, but just as applicable.

In reality this really isn't how code scans are done, so it's still a little silly, but I could theoretically see something like this being a desire.

It becomes more applicable, not just as applicable.

Amazon asked me to and I actually did it for all the Brazil third party imports...

granted it wasn't the most thorough of reviews, as is the nature with huge PRs

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.