Notifications
Clear all
Topic starter
July 4, 2026 7:01 pm
I was reading through the Goose install docs and noticed something. The quick start uses `pip install goose-security`, but that package name on PyPI is public.
Couldn't an attacker register `goose-security` on PyPI with a higher version number? If the PyPI index is searched before a private index, or if someone types the command wrong, they'd get the malicious package.
The Goose docs mention using `--index-url` for internal dependencies. But the default command doesn't. Is this a known risk? How does Goose's model handle this?