GeistHaus
log in · sign up

Settings

docs.astral.sh

uv is an extremely fast Python package and project manager, written in Rust.

7 pages link to this URL
Protect against supply-chain exploits using uv

LiteLLM was recently victim of a supply-chain exploit, where an attacker was able to run arbitrary code on infected machines. In the aftermath, I saw how uv provides a safety setting for this, and it would be good practice to add this to your pyproject.toml [tool.uv] exclude-newer = "1 week" or uv.toml: exclude-newer = "1 week" The docs provide multiple options to protect yourself.

0 inbound links en posts
Dependency Cooldowns¶

A guide to configuring dependency cooldowns across package managers to protect against supply chain attacks.