# Trusted libraries/packages - "package managers are evil"

**URL:** <https://discourse.julialang.org/t/trusted-libraries-packages-package-managers-are-evil/132320>\
**Category:** Internals & Design\
**Tags:** security, secrets\
**Created:** [September 12, 2025, 12:14pm UTC](https://discourse.julialang.org/t/trusted-libraries-packages-package-managers-are-evil/132320 "2025-09-12T12:14:04Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stevengj](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stevengj/32/71_2.png) [@stevengj](https://discourse.julialang.org/u/stevengj)\
**Post date:** [September 12, 2025, 12:39pm UTC](https://discourse.julialang.org/t/trusted-libraries-packages-package-managers-are-evil/132320/2 "2025-09-12T12:39:20Z")

</div>

> [@Palli](#):
>
> for that same package and without specifying the default would be trusted, status quo for now, maybe later untrusted and that would mean the code runs in a sandbox.

See e.g. [How to sandbox Julia code](https://discourse.julialang.org/t/how-to-sandbox-julia-code/76388) or [RFC / Discussion: Security and Julia · Issue #9744 · JuliaLang/julia · GitHub](https://github.com/JuliaLang/julia/issues/9744)

TLDR — sandboxing Julia packages is not really on the horizon.

> [@Palli](#):
>
> Odin language developer claims package managers are evil

Their argument is basically not to have dependencies that you don’t copy and distribute (“vendor”) yourself. Good luck with that. (Of course, this can be practical for a narrow set of applications.)

---

_[View the full topic](https://discourse.julialang.org/t/trusted-libraries-packages-package-managers-are-evil/132320)._
