This is a pre-production deployment of Warehouse. Changes made here affect the production instance of PyPI (pypi.python.org).
Help us improve Python packaging - Donate today!

Python Module Security Admonition

Project Description

If you are reading this admonition while running pip, I’d like to take this time to inform you that you just ran arbitrary code from the untrusted internet (maybe even as root?). The fact that this was so easy is a bit of a problem.

Remember when RubyGems.org got compromised and was down since they weren’t sure whether there were any problems with the gems themselves? That could have just as easily been PyPI. Adding SSL to PyPI and certificate checking to pip were big steps forward, but we need to make shipping and installing modules securely even easier. I’m not sure whether that means developer certificates or package signing or something else, but we need to find a way to run only trusted code. As long as a one character typo can root your box, the problem persists.

https://github.com/davidfischer/requestes

Release History

Release History

This version
History Node

0.0.1

Download Files

Download Files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

File Name & Checksum SHA256 Checksum Help Version File Type Upload Date
requestes-0.0.1.tar.gz (1.4 kB) Copy SHA256 Checksum SHA256 Source Jun 7, 2013

Supported By

WebFaction WebFaction Technical Writing Elastic Elastic Search Pingdom Pingdom Monitoring Dyn Dyn DNS Sentry Sentry Error Logging CloudAMQP CloudAMQP RabbitMQ Heroku Heroku PaaS Kabu Creative Kabu Creative UX & Design Fastly Fastly CDN DigiCert DigiCert EV Certificate Rackspace Rackspace Cloud Servers DreamHost DreamHost Log Hosting