aboutcode-org / aboutcode-org/python-inspector

Pip.conf settings are not parsed or respected

Open
#180 12 comments 2 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
23
Forks
28
PR merge metrics
No merged PRs in 30d

Description

An example pip.conf with sensitive variables changed to look like BASH variables:

```ini
[global]
extra-index-url = https://aws:${CODEARTIFACT_AUTH_TOKEN}@${DOMAIN}-${ACCOUNT_ID}.d.codeartifact.us-east-1.amazonaws.com/pypi/public-pypi/simple/
index-url = https://aws:${CODEARTIFACT_AUTH_TOKEN}@${DOMAIN}-${ACCOUNT_ID}.d.codeartifact.us-east-1.amazonaws.com/pypi/private-releases/simple/
```
These are actually set using the `pip config set global.extra-index-url` so they are presumably following the correct convention.

The file is located at `$HOME/.config/pip/pip.conf` following the [XDG_CONFIG_HOME](https://pip.pypa.io/en/stable/topics/configuration/#location) even when it is located in the legacy location `$HOME/.pip/pip.conf` it is not respected either.

The [pip documentation](https://pip.pypa.io/en/stable/topics/configuration/) in general.

EDIT: It also does not respect the relevant [environment variables either](https://pip.pypa.io/en/stable/topics/configuration/#environment-variables)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.