On third (last?) thought, I think PR
#4982 is well worth doing, but
not because Leo should install a minimal set of modules by default.
Indeed, the PR makes Leo's codebase (including unit tests) more resilient to missing modules, and will soon give better warnings when modules go missing. And that can happen: nothing prevents a user from uninstalling a module.
But restricting the modules that Leo installs will have virtually no effect on security. Leo installs well-known modules. Far more than Leo's integrity will be at stake if those modules become compromised.
Finally, installing a minimal set of modules complicates the user experience for all Leonistas, including devs.
Summary
PR
#4982 is worth doing for reasons
other than security.
After the PR is complete and passes all its tests (with minimal and full dependencies), I'll commit a version of pyproject.toml that:
- Installs all dependencies by default.
- Indicates (via commented-out sections) how optional dependencies could be specified.
All your comments, questions, and suggestions are welcome.
Edward