TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

PyPI has completed its first security audit

137 点作者 miketheman超过 1 年前

5 条评论

lyu07282超过 1 年前
Link to the report: <a href="https:&#x2F;&#x2F;github.com&#x2F;trailofbits&#x2F;publications&#x2F;blob&#x2F;master&#x2F;reviews&#x2F;2023-09-pypi-warehouse-securityreview.pdf">https:&#x2F;&#x2F;github.com&#x2F;trailofbits&#x2F;publications&#x2F;blob&#x2F;master&#x2F;revi...</a><p>They seem to not have analysed client-side of PIP itself, but I suppose there isn&#x27;t anything you could say that isn&#x27;t already obvious to everyone.
评论 #38266780 未加载
mrbonner超过 1 年前
My understanding reading the report is that the audit is for PyPI code and infrastructure itself and not the packages it hosts. Am I right?
评论 #38270691 未加载
thenerdhead超过 1 年前
Congrats! Thanks for trailblazing and being transparent to help other central registries follow.
the_common_man超过 1 年前
How much does an audit cost?
评论 #38267305 未加载
评论 #38267297 未加载
easylion超过 1 年前
Good to know. But how often are they going to do it ? Is it going to be an annual event from now on ?
评论 #38279813 未加载