3 ms·
For the non-install case, like when you're running a package index, having to eval the dependency specifying is horrible. This is also why wheels (the new pyth
by quodlibetor 10y ago
For the non-install case, like when you're running a package index, having to eval the dependency specifying is horrible.
This is also why wheels (the new python package format) use a static file instead of setup.py. The Python ecosystem has been trying to get off of "just eval setup.py" for years.
- xapata 10y agoI'm not sure why avoiding arbitrary code execution during install is important when you're going to do arbitrary code execution shortly after. What else is the purpose of installing a package?
- theptip 10y ago> For the non-install case, like when you're running a package index You have just ignored the point that your parent point was making. It's not the install case that they were complaining about.
- xapata 10y agoTrue. It's surprising to optimize for such a rare kind of user.
- baq 10y agotrying to not run arbitrary code on the enterprise network is prudent.
- xapata 10y agoBut that'd happen anyway when the installed package gets executed.