azure-devops-docs
azure-devops-docs copied to clipboard
Replace --extra-index-url with --index-url in docs
Using --extra-index-url
makes you vulnerable to dependency confusion attacks because it checks the PyPi repository for the package before it checks the custom repository. Thus it's better to use examples with --index-url
in docs instead, to avoid users thoughtlessly copying the snippet with possible vulnerabilities.
@MKapustin : Thanks for your contribution! The author(s) have been notified to review your proposed change.
@ramiMSFT
Can you review the proposed changes?
When the changes are ready for publication, add a #sign-off
comment to signal that the PR is ready for the review team to merge.
#label:"aq-pr-triaged" @MicrosoftDocs/public-repo-pr-review-team
@MKapustin Thanks for your contribution!
#sign-off