8 ms·
You can now uv run a GitHub gist
- BiteCode_dev 1y agoYou know how you can "uv run" python code from a text file using just a URL? No? Well, you can: uv run https://pastebin.com/raw/RrEWSA5F https://pastebin.com/raw/RrEWSA5F And since yesterday, you can even run a github gist: uv run https://gist.github.com/charliermarsh/ea9eab7f56b1b3d41e51960001cae31d https://gist.github.com/charliermarsh/ea9eab7f56b1b3d41e5196...
- unglaublich 1y agoOr more generally, pipe your script into stdin. > print("hi")' | uv run - > curl https://pastebin.com/raw/RrEWSA5F https://pastebin.com/raw/RrEWSA5F | uv run -
- abraham 1y agoYou can also get text from Gists by add .txt https://gist.github.com/charliermarsh/ea9eab7f56b1b3d41e51960001cae31d.txt https://gist.github.com/charliermarsh/ea9eab7f56b1b3d41e5196...
- BiteCode_dev 1y agoThis is what the code does more or less.
- charcircuit 1y ago"uv run" seriously needs a sandbox. Running arbitrary code from arbitrary dependencies with 0 version locking provides no guarantees on what you are actually running.
- unglaublich 1y agoYou can by set dependencies explicitly in the script's header. https://docs.astral.sh/uv/guides/scripts/#declaring-script-dependencies https://docs.astral.sh/uv/guides/scripts/#declaring-script-d...
- BiteCode_dev 1y agouv run is using virtual envs, that's the de facto standard, and those are sandboxes for python deps. So it already is. Plus inline deps mean you can pin python versions and 3rd party modules using pyproject.toml syntax in a comment of your script. This is not perfect locking, as it doesn't pin sub dependencies, but it's already more that any other tool out there. If you want perfect locking, create a project, and use uv lock. You are already in a different category of code.
- simonw 1y agoOP isn't talking about virtual environment style sandboxing, they're talking about sandboxes that prevent arbitrary code from deleting or stealing any information your user account has access to on your computer.
- throwaway290 1y agoRun it in a Docker container?
- cedws 1y agoDocker isn’t a sandbox and shouldn’t be treated like one. Admittedly if I’m going to run untrusted code I’ll run it in Docker, but I’m aware that whatever I’m running could break out. I wouldn’t blindly run some bullshit even in Docker unless I’m 90% sure it’s safe already.
- throwaway290 1y agoHow do you get to 90% sure for code that has any dependencies?
- OutOfHere 1y agoWhy is Docker (or extensions thereof) not a sandbox? Granted, it could access the internet, but that's necessary.
- simonw 1y agoImplementing sandboxes is really hard... but Astral are demonstrable great at solving hard problems. I dream of them one day saying "we've solved sandboxing for Python scripts" ala Deno https://docs.deno.com/runtime/fundamentals/security/ https://docs.deno.com/runtime/fundamentals/security/
- indigodaddy 1y agoThere’s lots of options not native to the tool. Just a few: devbox on MacOS. distrobox/toolbx on Linux. Project Bluefin has some really good ideas and concepts about all this: https://docs.projectbluefin.io/bluefin-dx/ https://docs.projectbluefin.io/bluefin-dx/
- rjh29 1y agoThat's the job of docker or systemd-nspawn. It shouldn't be implemented by every single command.
- OutOfHere 1y agodevcontainer builds upon it to further the sandbox.
- mvieira38 1y agoWhy is it their job to check for security? Sandboxing would make the ergonomics significantly worse for running quick scripts with uv run --script
- cipehr 1y agoI took gp’s comment to mean something more like deno. Deno is nice because you can explicitly allow/deny filesystem, network, etc. in an ergonomic way like `—-allow-fs` So not sure it would necessarily be ergonomically worse. It could even be a new run command `uv srun` or something…
- indigodaddy 1y agoBut uv isn’t a framework, isn’t that the difference, ie why they wouldn’t necessarily think it’s appropriate to delve into that particular territory?
- charcircuit 1y agoThis is like asking why do web browsers need to sandbox javascript. Giving full permissions to untrusted code is an attacker's dream.
- drewbitt 1y agoI have seen several Pyodide in Deno implementations lately.
- kortex 1y agoIt might be a cool thing for them to provide some kind of container metadata in the `# /// script` block so that e.g. it automatically runs the script in a container.
- vs4vijay 1y agoMaybe use along with "Pyodide"?
- paulbirch 1y agoThis is an interesting development, especially considering the growing trend of code-sharing platforms. As others have pointed out, this move by GitHub to allow UV to run GitHub Gists blurs the lines between code hosting and execution environments. It's worth noting that this also puts UV in direct competition with other code execution services like Repl. it and Google Colab, both of which have been gaining traction in the developer community. I'm curious to see how UV will differentiate itself in this crowded space.
- vs4vijay 1y agoDid you even read the article?
- kelsolaar 1y agoMmmmh I have been running from gists for ages, just use the full url as parameter...