Every package you install increases your risk
Every package you install increases your risk
Posted Aug 14, 2022 15:22 UTC (Sun) by Wol (subscriber, #4433)In reply to: Every package you install increases your risk by petiepooo
Parent article: Adding auditing to pip
> If you wish to audit a production environment, duplicate it in a lab and run your audit there. You already have a lab that duplicates your production environment, right?
WHAT production environment? WHO is paying for the lab?
I know there are a lot of people who are paid to write this stuff, but there are a lot of people who USE it in a *personal* capacity, and there are a lot of people who *write* it in a personal capacity.
If I'm writing/maintaining this stuff, I would love that sort of functionality. I have ONE powerful workstation / home-server, and I don't have the time, or money, to faff about trying to sort out a duplicate.
One *massive* advantage of this tool is that it would enable - in short order - popular packages to eliminate dependencies on abandoned packages. By reducing the amount of work needed to identify them, and massively increasing their visibility. A lot of the time people don't care because caring costs too much. Reduce that cost, and suddenly people will see the effort as worth while.
Cheers,
Wol
