|
|
|
|
|
by dumbo-octopus
953 days ago
|
|
Yes, because you could in theory run `pip install`, then manually read through every file you've just downloaded, then run `python myapp.py`. But every package manager seems to grant RCE to every installed package. I agree it's broken. |
|
This security model is utter nonsense because no one does this.