3 ms·
I personally treat it as a supply chain risk, as there are no longer any way to report any bugs and security problems.
by ZeroAurora 7mo ago
I personally treat it as a supply chain risk, as there are no longer any way to report any bugs and security problems.
- chrisjj 7mo agoThen why not provide one yourself?
- ZeroAurora 7mo agoForking is a good option for companies, but not a good option for sole developers: one doesn't have that much energy. Switching to other libraries like requests and aiohttp and supporting them by contributing is clearly a better option.
- nateb2022 7mo agohttps://github.com/MarkusSintonen/pyreqwest https://github.com/MarkusSintonen/pyreqwest is a great alternative, much more performant than requests/httpx/aiohttp, and provides an easy httpx compatible wrapper for migration.
- nijave 7mo agoNo need. There are plenty of other active alternatives
- dchest 7mo agoHow is _your_ supply chain a concern of this open source developer?
- ZeroAurora 7mo ago_My_ supply chain is not a big deal, lol. But this is HTTPX. A network library that has a considerable number of users. When I say _considerable_, I'm essentially saying _nearly every_ big tech. The one I can tell for sure is OpenAI (not a fan of them though). Remember xz attack?
- dchest 7mo agoWhy can nearly every big tech take care of their supply chain? :) Clearly, the maintainer doesn't want to do this job anymore, and it's not a requirement when releasing your code to also do stuff unrelated to programming.
- nijave 7mo agoThe parent poster never said it was. They just claimed it's risky for them which I agree with