[python-uk] Reviewing third-party packages

It's a question which interests me too. If you find some good resources, could you post them to this group?

Do you know how much checking is done on the Active State and Anaconda distributions?
> Are you able to recommend materials which deal with the *management precautions* one should take in reviewing a third-party package before use/inclusion in a wider system, please?
> There are plenty of resources available which deal with the coding-technical side of things, eg dir(), help(), PSL's inspect.py, etc.
> This enquiry encompasses those, but am particularly interested in security: back-doors, phoning-home, and other 'nasties'; license management; any costs; citation; etc.
> Will welcome references to articles, tutorials, check-lists, etc...
