Following symlinks should be optional
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 2.9k
- Forks
- 1.4k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 1
Description
Originally reported by: untitaker (Bitbucket: untitaker, GitHub: untitaker)
In #105 a change was made to follow symlinks while discovering package content. I propose that this behavior should be made optional or reverted. In my case my project directory accidentally included a symlink to another, very large project, and I ended up including a complete installation of ownCloud into a PyPI upload.
I'm willing to provide a patch for this.
This is a continuation of https://bitbucket.org/pypa/pypi/issues/293/re-uploading-of-releases-is-completely
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the change from issue #105 that made symlink following part of package-content discovery, along with the discussion and the linked continuation issue. Determine whether the behavior should be optional or reverted, and verify that a project symlink to a large external tree is not unintentionally included in a PyPI upload.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- build-system
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100