HelloZeroNet / HelloZeroNet/ZeroNet
please do not depend on python-pip3 - security risk - use dependencies available from distribution package repositories
- Dominant language
- JavaScript
- Stars
- 18.8k
- Forks
- 2.3k
- PR merge metrics
- No merged PRs in 30d
Description
Instructions on Linux currently require to run `sudo python3 -m pip install -r requirements.txt`. Please consider to drop this if possible.
python pip is a security risk since it does not verify software signatures on packages it downloads. It is also a third party package manager.
Previously a bitcoin wallet was hacked that depended on a third party package manager that didn't verify software signatures.
https://bitpay.com/blog/npm-package-vulnerability-copay/
Could you please use dependencies available from distribution package repositories such as packages.debian.org?
This is also a blocker for ever getting ZeroNet accepted into official packages.debian.org.
This is also a blocker for pre-installation of ZeroNet by default in Whonix.
Related packaging issues:
https://github.com/HelloZeroNet/ZeroNet/issues/382
https://github.com/HelloZeroNet/ZeroNet/issues/241
https://github.com/HelloZeroNet/ZeroNet/issues/1786
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by locating the Linux installation instructions that tell users to run `sudo python3 -m pip install -r requirements.txt`, then review `requirements.txt` and the related packaging issues #382, #241, and #1786. Done means the documented dependencies can be obtained from distribution package repositories instead of requiring pip, with the Linux instructions updated accordingly.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- build-system
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100