CPAN for python?

Randall Hopper aa8vb at yahoo.com
Thu Jun 8 14:46:35 EDT 2000


Thaddeus L. Olczyk:
 |Randall Hopper:
 |
 |>Wonder if Python could have something similar.  Folks could post URLs to a
 |>"getit.py" (or setup.py) script, and users could literally cut-and-paste
 |>this URL into a Python install tool that would just "do the install".  That
 |>is, don't bother them with where to FTP or surf, how to get the files,
 |>where to put the packages, what the name of the distdir in the tarball is,
 |>etc.  Just install the package and do what it takes to make it happen.
 |>That'd be cool.
 |
 |You've got to be kidding! 
 |Haven't you heard of "melissa" or "ILoveYou"?

Hey, I didn't mean to get your dander up on this.  Far be it from me to
suggest solutions on par with MSWindows joke security where users just
click on attachments to nuke their machine.  [[ Executable .vbs attachments
look like text attachments, the Windows Scripting Host enabled by default,
users having no idea where an e-mail with attachment really came from, most
installations having no concept (or having negated) the concept of a
priviledged user -- no, nothing so silly. ]]

Relevent differences: in this case, the user proactively "pulls" a
port/module dist/getit.py from a "trusted" host.  None of this insecure
push nonsense.  And if it's not from a trusted host, it's up to the user to
make the call whether they'll download and install the module dist.

I credit Python folks with more intelligence than Outlook users mindlessly
click on e-mail attachments, not really knowing what's hinding underneath.

-- 
Randall Hopper
aa8vb at yahoo.com




More information about the Python-list mailing list