Open source security at Astral

35 points by freddyb


prez

Lots of words, they should fix uv add (just like pip install) being RCE instead.

Being a python developer is living on the edge, just earlier today I installed a typo squatted numpy variant. Fun.