Yes, because you could in theory run `pip install`, then manually read through every file you've just downloaded, then run `python myapp.py`.
But every package manager seems to grant RCE to every installed package. I agree it's broken.
But every package manager seems to grant RCE to every installed package. I agree it's broken.
This security model is utter nonsense because no one does this.
In reality this really isn't how code scans are done, so it's still a little silly, but I could theoretically see something like this being a desire.
granted it wasn't the most thorough of reviews, as is the nature with huge PRs
pip download?