Incorrect zstandard dependency on master
envgap__dpkp__kafka-python-2350
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not scored yet.
- The failure reproduces in a clean container and the known fix makes the project run; it has not been scored yet.
02 / ENVIRONMENT RECIPE
- Base commit
d9201085f021aaa376b6ef429f9afc2cc4d29439- Manifest
setup.py- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
dpkp/kafka-python #2350 · read the original issue
See comments [here](https://github.com/dpkp/kafka-python/pull/2123#discussion_r1084195304). There is no `python-zstandard` package on PyPI which makes this a security issue because a bad actor can claim that name and publish a malicious package. I believe this should really point to just `zstandard`. Also, even if just for the sake of checking installation, it would be great if this is actually covered by CI, ie checking that installing all the extras works without blowing up.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]