4 ms·
I am looking forward to PyPI's "answer" to this class of malicious packages with automated third-party reporting (and hopefully long-term, quarantining or even
by SethMLarson 3y ago
I am looking forward to PyPI's "answer" to this class of malicious packages with automated third-party reporting (and hopefully long-term, quarantining or even deletion). Hopefully this project will swing the narrative closer to the /actual/ security threat that these packages represent to their respective package ecosystems. The PyPI Safety and Security Engineer Mike Fiedler is working on this project :)
- woodruffw 3y agoYes! I think an under-considered aspect here is that this kind of high-volume malicious package activity isn’t particularly dangerous in and of itself, but does represent a operational/sustainability risk w/r/t compromising the index’s abilities to respond to actual urgent issues in a timely manner. More automation (reporting, quarantining) goes a long way towards addressing that. It’s more the language of compromise I resent: I think treating every low-effort malicious spam package as a fundamental risk unnecessarily “spends” the security mindshare budget that engineers keep in reserve. But I think my opinions there are already well-known :-)