logoalt Hacker News

sdoeringyesterday at 7:42 PM1 replyview on HN

Sorry - call me uninformed. But I do not really understand how choosing uv makes me less safe than using pip.

Care to explain? Would love to learn.


Replies

jcass8695yesterday at 7:46 PM

It is a bit of a leap. They are saying that if you are using uv, then you likely have a broad set of dependencies because you require a dependency management tool, therefore you are more susceptible to a supply chain attack by virtue of having a wider attack surface.

show 1 reply