Every package you install increases your risk
Every package you install increases your risk
Posted Aug 11, 2022 19:08 UTC (Thu) by petiepooo (guest, #153884)Parent article: Adding auditing to pip
One of the best ways to ensure your installation is not vulnerable is to limit the packages you install to only those necessary. By that tenet, simply installing pip-audit increases your attack surface and therefore your vulnerability.
While I understand the value of the audit tooling, I feel the drive to make it ubiquitous by integrating it into pip could ultimately increase people's exposure to risk rather than decrease it. If you wish to audit a production environment, duplicate it in a lab and run your audit there. You already have a lab that duplicates your production environment, right?
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
