(FWIW, I don't think the security posture of pip is obvious to everyone[1], and I do think it would benefit from a separate audit!)
(FWIW, I don't think the security posture of pip is obvious to everyone[1], and I do think it would benefit from a separate audit!)
`pip download --no-deps` allowing arbitrary code-execution is non-obvious, and IMO broken.
But every package manager seems to grant RCE to every installed package. I agree it's broken.
This security model is utter nonsense because no one does this.
In reality this really isn't how code scans are done, so it's still a little silly, but I could theoretically see something like this being a desire.
granted it wasn't the most thorough of reviews, as is the nature with huge PRs
pip download?
Evil Joe: Can you install this package in the system's python install? All users in the lab need it.
Naive Joe: Hm... Seems harmless enough enough. Let me just install locally and check if there aren't any setuid binaries in there
naivjoe:~ $ pip install --local getpwned
... checks all installed binaries look good ...
Naive Joe: Funny package name
naivjoe:~ $ sudo pip install getpwned
Naive Joe: Done!
Evil Joe: Thanks! evil laugh
Naive Joe: uh what's so funny?
Evil Joe: Nothing.
Careless, amateurish? Maybe. Obvious? Maybe not.