Title: "install" package on PyPI
Author: Jared Ondricek (flamableconcrete) Date: 2021-04-09 16:50
I recently accidentally typed "pip install pip install <package-i-really wanted>" and it installed a package called "install" that has 1 star on GitHub. It is also in use by 2.3k repositories according to the GitHub dependency graph view. I don't think it's malicious, but it does seem a bit sketchy. I just know this sort of thing has been in the news lately, and maybe this is that sort of thing that ought to be looked at by someone smarter than me about security stuff.

The way Perl deals with this specific issue is by using a specific dummy module so no one can do this on accident.

Is this worth the time to discuss? Or am I just being paranoid about a third party library called install?

PyPI entry:
GitHub page:
GitHub projects that depend on it:
Perl dummy install module:
Author: Christian Heimes (christian.heimes) Date: 2021-04-09 17:27
BPO is just for CPython bugs. Packaging and PyPI are handled by different teams and trackers. Please use
Author: Karthikeyan Singaravelan (xtreak) Date: 2021-04-09 17:51
This seems to have been discussed :
Author: Terry J. Reedy (terry.reedy) Date: 2021-04-10 03:06
And maybe discuss with pip people why 'pip install pip install zyx' is not caught as an error.
