Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add shadowing warning to supplemental source docs #8733

Merged
merged 1 commit into from
Dec 4, 2023
Merged

Add shadowing warning to supplemental source docs #8733

merged 1 commit into from
Dec 4, 2023

Conversation

JockeTF
Copy link
Contributor

@JockeTF JockeTF commented Dec 1, 2023

We may want people to consider what happens if someone publishes a new package to PyPI which matches one in their supplemental source. There were a few dependency confusion vulnerabilities a while back that were caused by something similar. I presume lock files help to some extent though.

Pull Request Check List

Resolves: None

  • Added tests for changed code.
  • Updated documentation for changed code.

@radoering radoering added the impact/docs Contains or requires documentation changes label Dec 4, 2023
Copy link

github-actions bot commented Dec 4, 2023

Deploy preview for website ready!

✅ Preview
https://website-d2ocmrn2t-python-poetry.vercel.app

Built with commit b810729.
This pull request is being automatically deployed with vercel-action

docs/repositories.md Outdated Show resolved Hide resolved
@radoering radoering merged commit a31d00b into python-poetry:master Dec 4, 2023
18 checks passed
MrGreenTea pushed a commit to MrGreenTea/poetry that referenced this pull request Dec 18, 2023
Copy link

github-actions bot commented Mar 3, 2024

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Mar 3, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
impact/docs Contains or requires documentation changes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants