Reply to post:

Boffins rate npm and PyPI package security and it's not good

DomDF

It's considered very bad practice to have pinned dependencies in libraries on PyPI. It's fine for applications, but PyPI isn't geared towards distributing them. Why then is pinning being recommended here?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon