Skip to content

Conversation

sobolevn
Copy link
Contributor

@sobolevn sobolevn commented Jun 8, 2024

@srittau srittau merged commit 734c5ff into typeshed-internal:main Jun 11, 2024
@Akuli
Copy link

Akuli commented Jun 11, 2024

I don't like how we need to add relatively obscure packages to a global allowlist, but I'm not sure if there is a better solution. I guess we just need to carefully avoid step 6 of #61 (comment).

That said, it would be nice to document the security aspects of stub_uploader somewhere, maybe to a markdown file in this repo, instead of referring to old PR comments whenever security comes up. I might give it a try within the next few weeks.

Security is IMO the most important thing for stub_uploader to get right, because a malicious types_requests could very quickly gain access to many dev machines, and from there to many production servers and such.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants