HelloZeroNet / HelloZeroNet/ZeroNet

please do not depend on python-pip3 - security risk - use dependencies available from distribution package repositories

Open
#2,326 25 comments 1 reaction 0 assignees View on GitHub
Dominant language
JavaScript
Stars
18.8k
Forks
2.3k
PR merge metrics
No merged PRs in 30d

Description

Instructions on Linux currently require to run `sudo python3 -m pip install -r requirements.txt`. Please consider to drop this if possible.

python pip is a security risk since it does not verify software signatures on packages it downloads. It is also a third party package manager.

Previously a bitcoin wallet was hacked that depended on a third party package manager that didn't verify software signatures.

https://bitpay.com/blog/npm-package-vulnerability-copay/

Could you please use dependencies available from distribution package repositories such as packages.debian.org?

This is also a blocker for ever getting ZeroNet accepted into official packages.debian.org.

This is also a blocker for pre-installation of ZeroNet by default in Whonix.

Related packaging issues:

https://github.com/HelloZeroNet/ZeroNet/issues/382
https://github.com/HelloZeroNet/ZeroNet/issues/241
https://github.com/HelloZeroNet/ZeroNet/issues/1786

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by locating the Linux installation instructions that tell users to run `sudo python3 -m pip install -r requirements.txt`, then review `requirements.txt` and the related packaging issues #382, #241, and #1786. Done means the documented dependencies can be obtained from distribution package repositories instead of requiring pip, with the Linux instructions updated accordingly.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
build-system
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.