Installing packages (i.e. source code) for programming languages should not execute arbitrary code.
Installing packages (i.e. source code) for programming languages should not execute arbitrary code.
Seems like prohibiting arbitrary code in installation scripts would only help with issues like Bumblebee's `rm -rf`: https://github.com/MrMEEE/bumblebee-Old-and-abbandoned/issue...
True, but in the case I've mentioned, if you've mistyped the name of the package, you can safely uninstall it without any issues.
Furthermore, code is often ran in (sort of) sandboxed environments like Docker during development, in which case arbitrary code on runtime is less dangerous than arbitrary code on install time.
> Furthermore, code is often ran in (sort of) sandboxed environments like Docker during development, in which case arbitrary code on runtime is less dangerous than arbitrary code on install time.
Wouldn't the package install then also happen in a Docker container anyway, negating the problem? Or how would you install a package to your host environment and then use it from within a container?
It can give people also a second change to notice, e.g. the typo in the package name.
Actually it is even worse because JS is more popular and average JS dependency tree is so much more massive. Any tiny forgotten transitive dependency of a dependency (or dev dependency) 15 layers deep can pull this off. Total leftpadization is not a thing on pypi due to different culture
There is the reductive argument that basically everything you download is arbitrary code, but throwing away the code that is run seems uniquely silly.
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
curl | tee saved.sh | sh
thenYou also shouldn’t be able to push code directly to anywhere other than a centralized repository. All the build stuff should happen in a dedicated and independent process.
From a security point of view you need to accept that the idea of running into a malicious package as a direct or indirect dependency is not only not zero but fairly realistic and you should try to limit the blast radius as much as possible for when that does happen.
But an attacker could infiltrate them by manipulating magnetic fields to generate keystrokes / mouse moves so also faraday cage them.
That way you could pick a repo based on your risk appetite rather than needing to trust PyPI. Debian style python for the cautious and AUR style python for the bleeding edge and reckless.
But setup.py is part of the Python's legacy, from before PyPI even existed.
I can install python-matplotlib from my package manager, and it appears in my python path. I never bother with venvs.
Maybe my needs aren't advanced (or exotic) enough.
Tell that to JS, Python and Rust people.
But hey, we are secure. /s