Antoine Pitrou added the comment:

> How shall I handle venv? I'm reluctant to disable venv in
> although it allows a user to modify sys.path. However it's only an
> issue under two circumstances:
> (1) The user either needs write permissions to the parent directory of
> the python executable. 
> (2) The script doesn't hard code the path to the interpreter in its
> shebang.
> Point 1 allows the user to mess with the system in more serious ways.
> The second point can be avoided with a correctly written shebang line.

I agree that venv shouldn't be a problem.


