logoalt Hacker News

quectophotonyesterday at 10:26 PM1 replyview on HN

I wouldn't say without fear, since you're one typo away from executing a typo-squatted malicious package.

I do use it on CI/CD pipelines, but I wouldn't dare type uvx commands myself on a daily basis.


Replies

stavrosyesterday at 10:45 PM

uvx isn't more risky than `pip install`, which is what I used before.

show 1 reply