Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Transitive dependency (termcolor) does not have wheel #171

Closed
matthewdeanmartin opened this issue Dec 7, 2021 · 2 comments · Fixed by #207
Closed

Transitive dependency (termcolor) does not have wheel #171

matthewdeanmartin opened this issue Dec 7, 2021 · 2 comments · Fixed by #207
Labels

Comments

@matthewdeanmartin
Copy link

matthewdeanmartin commented Dec 7, 2021

I'm working on getting security packages to have the option of installing with only wheels (it's more secure that way), ref. Jake which means the whole dependency graph needs to have wheels

yaspin's dependency on termcolor (which has no wheels and has no maintainer, so it is hard for me to get a wheel in termcolor)

I did create a fork, termcolor-whl so you could switch to that or venderize termcolor.

Without something like that, people who depend on yaspin would have to vendorize to get around the problem.

@pavdmyt
Copy link
Owner

pavdmyt commented Dec 10, 2021

Hi @matthewdeanmartin

Thanks for pointing this out and detailed description for potential security issues 👍
I'll probably vendor termcolor, as it was before this commit: d19bbe7

pavdmyt added a commit that referenced this issue Jul 21, 2022
@pavdmyt
Copy link
Owner

pavdmyt commented Jul 21, 2022

The fix will be included into the next release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants