logoalt Hacker News

digganyesterday at 11:49 AM0 repliesview on HN

> security breakdown of uv versus pip versus conda versus whatever fashionable package manager

In the end, every package manager (so far at least) download and runs untrusted (unless you've verified it manually) 3rd party code. Whatever the security difference is between uv and pip implementation-wise is dwarfed compared to if you haven't found a way of handling untrusted 3rd party code yet.