<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: CML Python Package Installation Security in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/CML-Python-Package-Installation-Security/m-p/381738#M244382</link>
    <description>&lt;P&gt;pip index url can be configured as an admin environment variable, but users can override the same with the project environment variable or manual override.&lt;BR /&gt;&lt;BR /&gt;utmost way is to make the cluster air gapped. As long as the cluster has internet gateway, sessions can reach internet to pull the packages&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2024 10:22:52 GMT</pubDate>
    <dc:creator>Gopinath</dc:creator>
    <dc:date>2024-01-08T10:22:52Z</dc:date>
    <item>
      <title>CML Python Package Installation Security</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CML-Python-Package-Installation-Security/m-p/381690#M244369</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've noticed how the CML Terminal lets you install Python packages on the 'Net using pip.&lt;/P&gt;&lt;P&gt;(A gcc compiler is even available!)&lt;/P&gt;&lt;P&gt;Isn't that a security risk?&lt;/P&gt;&lt;P&gt;Is there a way to only allow package installation from an in-house repository?&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 06:44:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CML-Python-Package-Installation-Security/m-p/381690#M244369</guid>
      <dc:creator>phir1</dc:creator>
      <dc:date>2026-04-21T06:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: CML Python Package Installation Security</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CML-Python-Package-Installation-Security/m-p/381738#M244382</link>
      <description>&lt;P&gt;pip index url can be configured as an admin environment variable, but users can override the same with the project environment variable or manual override.&lt;BR /&gt;&lt;BR /&gt;utmost way is to make the cluster air gapped. As long as the cluster has internet gateway, sessions can reach internet to pull the packages&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 10:22:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CML-Python-Package-Installation-Security/m-p/381738#M244382</guid>
      <dc:creator>Gopinath</dc:creator>
      <dc:date>2024-01-08T10:22:52Z</dc:date>
    </item>
  </channel>
</rss>

