A new home for Python-build-standalone
astral.sh
astral.sh
> So, for example, when you download Python on Linux (e.g., from python.org), what you're actually downloading is the CPython source, which is then built on your machine.
But python.org does provide prebuilt macOS binaries. How is that accomplished and why doesn't whatever they're doing generalize to Linux?
A big holdup seems to be who would maintain this in the CPython project. Perhaps some Astral folks could become core devs as well and maintain it upstream
I would advise against Astral for maintaining anything inside the Python organization. Too much talk, power plays and no real software engineering.
Source needed.
Pun unintended.
The discussions around lockfiles, dynamic metadata or PyBI (the PEP that wanted to address what python-build-standalone does) are good examples of how hard it is to cause change in that space.
I’m optimistic the Astral folks will have better success than me and I support them in their efforts. They have viable, popular solutions in hand. Hopefully that helps convert others to their cause. “If you build it they will come.”
One of the consequences of framework builds is that they have a different layout than a regular Python installation on the file system. The Python installer will also litter a bunch of files into /Applications which makes installing competing versions surprisingly annoying.
In theory a framework build of Python would be preferrable but the framework build would have to become fully relocatable for that benefit to pay off. They are not today.
This should be illegal.
That happens all the time. Who builds the docker images you are using?
> You've added another link in your software supply chain. How do you know they haven't inserted malware?
You're installing untrusted random packages from PyPI. There are many much weaker points than Astral giving you malware for fun.
FYI there are two parties you are talking about: Astral, and GitHub too (if you don't trust Microsoft).