4 ms·
Feel free to elaborate.
by jonathrg 2y ago
Feel free to elaborate.
- TZubiri 2y ago''' in python are there any libraries where the pip install command is different than import?" ChatGPT: Yes, there are some Python libraries where the `pip install` command differs from the module name you use for `import`. Below are a few examples of such cases: 1. *`pip install opencv-python`* - Import as: `import cv2` 2. *`pip install beautifulsoup4`* - Import as: `from bs4 import BeautifulSoup` 3. *`pip install PyMySQL`* - Import as: `import pymysql` 4. *`pip install python-dateutil`* - Import as: `import dateutil` 5. *`pip install python-dotenv`* - Import as: `import dotenv` 6. *`pip install google-auth`* - Import as: `import google.auth` 7. *`pip install Pillow`* - Import as: `from PIL import Image` ''' It seems that the project hardcodes the import to pypi names though. So it has a that sweetspot of being more impractical while still being insecure. https://github.com/bndr/pipreqs/blob/master/pipreqs/mapping https://github.com/bndr/pipreqs/blob/master/pipreqs/mapping If you install this in a company that takes security seriously, you should get warned or fired pretty much. It's one thing to import code from a random developer on the internet to do your job, we get a pass on that if it makes us more productive, but to import code that helps us with importing code? Red flag.
- jonathrg 2y agoHow is it more secure to manually browse through the codebase and construct a requirements.txt file yourself, than to run this script to automate the process? In either case you end up with a requirements.txt file which will need to be audited anyway.
- TZubiri 2y agoI guess that it's more of a semantic implication of the tool. If the project were to create a directory that maps python namespaces to pypi tools, sure. But it's designed as a "tool" that "automates" a pesky little inconvenience of a missing requirements.txt file. The readme explains in no way how that mapping works or any security considerations. It doesn't give me the impression that the author or the users would care about auditing the requirements.txt file at all. (Also, what would auditing the dependencies entail? Reading the source code of the dependencies? Doubt it.)