|
|
|
|
|
by fragmede
234 days ago
|
|
Just a heads up that Pypi isn't immune from the same attack, with "Pypi supply chain attack" into Google revealing a (much smaller) number of packages that turned out to be malware. Some were not misspellings either, with one being a legitimate package that got hacked via GitHub Actions and a malicious payload added to the otherwise legitimate package. |
|
Having a large standard library does reduce the number of dependencies, and you can go a long way using only well known dependencies.