Tag
setuptools
Safeguard articles tagged "setuptools" — guides, analysis, and best practices for software supply chain and application security.
3 articles
Vulnerability Analysis
Python setuptools package_index ReDoS (CVE-2022-40897)
CVE-2022-40897 is a ReDoS flaw in setuptools' package_index.py that can hang CI pipelines when parsing crafted index pages. Here's how to detect and fix it.
Dec 31, 20257 min read
DevSecOps
Is Python setup.py Still Safe? Security Risks and the Move to Building Wheels
python setup.py executes arbitrary code at install time and its legacy commands are deprecated. Here is what that means for security and how to build a wheel the modern way.
Apr 22, 20255 min read
Open Source Security
Python setuptools Security Considerations
setuptools is the default Python packaging backend and its security properties matter for anyone who builds, installs, or runs Python code. Here is what to watch.
Oct 5, 20237 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.