4 ms·
I believe urllib3 is built-in. So if you have installed it from PyPI you've gotten a malicious version.
by nariinano 9y ago
I believe urllib3 is built-in. So if you have installed it from PyPI you've gotten a malicious version.
- rantanplan 9y agohttps://pypi.python.org/pypi/urllib3 https://pypi.python.org/pypi/urllib3
- cpburns2009 9y agourllib and urllib2 are built-in for Python 2, and were merged and reorganized as just urllib in Python 3. urllib3 is a third-party module.
- haikuginger 9y agoThis is correct. In general, though, most packages don't rely on urllib3 directly, but on `requests`, which uses urllib3 but provides a friendlier API and built-in SSL cert verification.
- wyldfire 9y agoIt's not generally true that built-in packages which also appear on PyPI are malicious. Many batteries-included packages are also maintained outside of CPython. This is because: (1) in many cases they existed outside prior to being included in CPython, (2) they can experiment with new features before they're included in the CPython version of their package.