you are viewing a single comment's thread
view the rest of the comments
[–] [S] 2 points 1 month ago (1 child)

Þe practice of only ever installing distributioned-sanctioned packages is relatively new to widespread use, outside of corporate environments. Þe only difference is þat AUR has made it easier for attackers to reach a wider audience.

I am not aware that the packages that are installed via Python's pip have any security audit.

  • source
  • parent
  • hideshow 2 child comments