Skip to content

Conversation

celskeggs
Copy link

This PR is intended to solve issue #262, about the pip automatic installation feature being a potential security concern.

Would you consider merging this pull request to remove the feature in question?

I believe that I ran the regression tests properly, but it is possible that I missed something.

This was flagged as a security risk of using this module.
@celskeggs
Copy link
Author

@fralau Apologies for bothering you about this again... I am wondering whether you've made a decision on whether you want to implement the change requested in #262? If so, I am wondering whether this PR meets your requirements or whether you are looking for another solution?

@fralau
Copy link
Owner

fralau commented Sep 8, 2025

I am agreeing with the principle of not doing the install. I will probably apply a slightly different approach, though.

@fralau fralau closed this Sep 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants