|
|
Log in / Subscribe / Register

Adding auditing to pip

Adding auditing to pip

Posted Aug 16, 2022 10:29 UTC (Tue) by amarao (guest, #87073)
Parent article: Adding auditing to pip

I just checked pip-audit output for some random image we have, and few 'CVE' caught my attention. One of which, turned out, is just an opinion of 'how things should be in Ansible' (https://github.com/advisories/GHSA-h39q-95q5-9jfp), with extremely worrying description, which turned out to be sec-click-bait (https://github.com/ansible/ansible/issues/67792#issuecomm...). Nevertheless, the CVE is issued and there is no way back - it's FOREVER UNFIXED and SECURITY IS ENRAGED. I saw a lot of 'security officers' who just ignore the matter and have KPI of 'no CVE', which brings us to the problem: one guy screamed 'CVE' and no one else can undo this scream. And there are other guys with power to follow this scream and to break production BECAUSE OF SECURITY.


The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds