Bugzilla – Bug 1143662
AUDIT-FIND: obs-service-python_sdist: runs untrusted setup.py
Last modified: 2022-02-24 09:44:00 UTC
runs untrusted setup.py
It does, but that's kind of the point here ;) The alternative would be that user runs it himself, so I see no additional exposure. It abstracts that a bit so that users might not be as aware, but OTOH this is used by experienced users that should know that.
I still see it this way. Reopen if you disagree