20
votes

Can't remember where I read this, but either somewhere on here or in the comments of a tutorial I was following, a person said:

'Never never ever use sudo pip install; you could overwrite important stuff without knowing it. Use pip install --user instead!'

I see lots of references to sudo pip install everywhere though, so did this person know what they were talking about and I should avoid it, or... ?

2
In theory, a malicious package can install/read/modify/delete any file it has access to through various directives specified in its setup.py file. Installing with sudo widens the number of files / locations that can be modified. You're basically allowing unvetted code root access to your system. In practice, when installing packages from trusted authors, you're unlikely to get burnt -- at least not significantly more vulnerable than installing a package from your distro's package manager. That being said, the --user switch is available and should be seriously considered. - jedwards
I have used sudo pip countless times without ever encountering an issue, once you trust the source I would not worry about it. - Padraic Cunningham
To anyone interested, there's a pretty good answer to a similar question here - bruno desthuilliers

2 Answers

10
votes
$ sudo pip install 

Installs the package globally in your python installation, i.e. for all users.

$ pip install --user

Installs to the local user directory, i.e. ~/.local/lib/python -- just you.

Example:

$ sudo pip install jupyter
$ jupyter notebook

Will run jupyter, open a web browser, allow you to work with notebooks.

$ pip install --user jupyter
$ jupyter notebook

Will do nothing until your local directory has been added to your PATH.

There was recently malicious code included in pypi. Never use sudo to install with pip. This is the same as running a virus as root. Either add your local folder to your PATH or use a virtualenv.

5
votes

sudo pip install probably means that you want to install a package system-wide. For some packages, such as virtualenvwrapper, that might be useful, but besides that I'd avoid installing system-wide packages and create a virtualenv for each application and pip install to that virtualenv (which can be done without sudo).