Skip to content

Reject locked malware installations #18781

@woodruffw

Description

@woodruffw

If the user's uv.lock contains a version that is known to be malicious, then we should reject its installation.

This is slightly different from what uv audit does -- uv audit principally checks from known vulnerabilities, not malware or compromised packages. The latter is reported via a distinct "stream" on OSV (MAL- reports).

I need to think a bit more about the design here/implications.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or improvement to existing functionality

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions