# How do (long held) security concerns in Python’s \`pip\` relate to Julia’s \`Pkg\`?

**URL:** <https://discourse.julialang.org/t/how-do-long-held-security-concerns-in-python-s-pip-relate-to-julia-s-pkg/72198>\
**Category:** Internals & Design\
**Tags:** question\
**Created:** [November 28, 2021, 1:55pm UTC](https://discourse.julialang.org/t/how-do-long-held-security-concerns-in-python-s-pip-relate-to-julia-s-pkg/72198 "2021-11-28T13:55:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cadojo](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/cadojo/32/25328_2.png) [@cadojo](https://discourse.julialang.org/u/cadojo)\
**Post date:** [November 28, 2021, 1:55pm UTC](https://discourse.julialang.org/t/how-do-long-held-security-concerns-in-python-s-pip-relate-to-julia-s-pkg/72198/1 "2021-11-28T13:55:45Z")

</div>

I’ve learned that, for a while, folks have noted some security concerns with Python’s `pip` because packages can execute code arbitrarily on install.

I believe Julia’s `Pkg` can _also_ execute code arbitrarily on install through the `build` step, right? Is there a similar concern with arbitrary code execution in `Pkg`? Or has this issue somehow been addressed?

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [November 28, 2021, 2:05pm UTC](https://discourse.julialang.org/t/how-do-long-held-security-concerns-in-python-s-pip-relate-to-julia-s-pkg/72198/2 "2021-11-28T14:05:44Z")

</div>

The `Pkg.build` step is somewhat deprecated, I think very few packages use it nowadays, also to promote immutability of packages directories. But in the end, why worrying about arbitrary code run during the `build` step if the package you’re going to install can also run arbitrary code?

---

<div class="post-metadata">

**Author:** ![cadojo](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/cadojo/32/25328_2.png) [@cadojo](https://discourse.julialang.org/u/cadojo)\
**Post date:** [November 28, 2021, 2:48pm UTC](https://discourse.julialang.org/t/how-do-long-held-security-concerns-in-python-s-pip-relate-to-julia-s-pkg/72198/3 "2021-11-28T14:48:52Z")

</div>

> But in the end, why worrying about arbitrary code run during the `build` step if the package you’re going to install can also run arbitrary code?

Ah didn’t know that about `Pkg.build`, good to know.

> But in the end, why worrying about arbitrary code run during the `build` step if the package you’re going to install can also run arbitrary code?

Agreed, that makes sense. But I do see Python folks worrying about this. Now I’m curious why.

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [November 28, 2021, 3:00pm UTC](https://discourse.julialang.org/t/how-do-long-held-security-concerns-in-python-s-pip-relate-to-julia-s-pkg/72198/4 "2021-11-28T15:00:41Z")

</div>

> [@cadojo](#):
>
> Agreed, that makes sense. But I do see Python folks worrying about this. Now I’m curious why.

I mean, it is indeed nice to avoid extra steps which can do anything during the installation process. If Julia was able to just drop `Pkg.build` (not possible within the 1.x series), package directories could be made completely read-only and could be checked for integrity with the git-tree-sha1. I’m not sure that’s done at the moment, since `Pkg.build` can potentially write to the `deps/` directory. For example, the pull request [Require Julia 1.6+, use Preferences, eliminate mutable state by staticfloat · Pull Request #189 · JuliaMath/FFTW.jl · GitHub](https://github.com/JuliaMath/FFTW.jl/pull/189) removed the need to run `Pkg.build` for `FFTW.jl`, making the package immutable and more precompilation-friendly.

Regarding Python packaging, I don’t know if they have other options at all?
