pip + safety

Julian Berman <[email protected]>
Newsgroups gmane.comp.python.distutils.devel
Message-ID <CABJQSkkeiiDCHYE7m2DDVA5c2jErfFAWzNJ6OMr7W15mg4R0wQ@mail.gmail.com>
Hi.

I recently found myself installing a node.js package, and in the process
noticed that (sometime recently?) it started automatically warning about
known vulnerabilities during installation of package.jsons (see
https://docs.npmjs.com/cli/audit).

At work, we run safety (https://pypi.org/project/safety/) on all our
projects (which has both free and paid versions). It's great.

I know there's a ton of wonderful work happening at the minute to improve
underlying scaffolding + specification to enable tools other than
setuptools + pip to thrive, so maybe this is the wrong moment, but I
figured I'd ask anyways :) -- what are opinions on running a similar thing
during pip install?

-J

--
Distutils-SIG mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3/lists/distutils-sig.python.org/
Message archived at https://mail.python.org/archives/list/[email protected]/message/WPQDP73N7IINXX36UAOG7YDYHD7MYU4X/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.