mistersql,
@mistersql@mastodon.social avatar

When someone republishes an identical (?) copy of a major package under their own name on , that's probably malicious right? This is a variation on typosquatting.

https://pypi.org/user/LukeSamkharadze/

mistersql,
@mistersql@mastodon.social avatar

Today I learned about the inspector website, browse the contents of a package before you install it! Much easier than the download, unzip, etc.

https://inspector.pypi.io/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • python
  • DreamBathrooms
  • mdbf
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • InstantRegret
  • tacticalgear
  • anitta
  • ethstaker
  • provamag3
  • cisconetworking
  • tester
  • GTA5RPClips
  • cubers
  • everett
  • modclub
  • megavids
  • normalnudes
  • Leos
  • JUstTest
  • lostlight
  • All magazines