-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Closed
Description
Currently get-pip.py is downloaded from a remote server and installed without checking that it's legitimate [1]
I'm aware that there's no official way to verify the downloaded file and also that it might change at any time, so IMHO it might be good to keep a local, known to be good, version of that file and update it from time to time.
[1]
Line 110 in 13ae0c0
| wget -O get-pip.py 'https://bootstrap.pypa.io/get-pip.py'; \ |
ulgens
Metadata
Metadata
Assignees
Labels
No labels