Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Would sticking to the OS upstream package manager be a safer option compared to installing from pypi directly?

How often does something like this happen with packages in the CentOS, epel, or Debian repositories?



I think it would be quite a bit safer and you are already trusting your distribution but those libraries tend be very old/stale versions, and limited selections.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: