Dear #Python devs: I'm reading this: http://ow.ly/kbIcn - How are virtualenvs not a security nightmare?
-
-
@standaloneSA Are they worse than other forms of deployment bundling and static linking for local apps? All need security issue tracking.0 retweets 0 likes -
@thatcks I agree, but it seems like it would encourage fragility, wouldn't it? I've got no experience to draw from in this case, though.0 retweets 0 likes -
@standaloneSA I see it as anti-fragility unless you have a lot of trust in your OS vendor's package updates to be totally stable.0 retweets 0 likes -
@thatcks As long as the entire chain of test and deploy are all running the versions, but doesn't it make it hard for others to code on?0 retweets 0 likes
@standaloneSA An artisanal handcrafted virtualenv is not really different from an artisanal handcrafted production server or dev machine.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Matt Simmons
Chris Siebenmann