[HN Gopher] PyPI Introduces "Trusted Publishers"
___________________________________________________________________
PyPI Introduces "Trusted Publishers"
Author : BerislavLopac
Score : 20 points
Date : 2023-04-20 21:14 UTC (1 hours ago)
(HTM) web link (blog.pypi.org)
(TXT) w3m dump (blog.pypi.org)
| woodruffw wrote:
| I'm one of the people who helped design and build this
| functionality; happy to answer any questions about it!
| morkalork wrote:
| When I first read the title I was hoping for something like "we
| have added a layer of curation and verification to pypi in
| response to malicious packages being published". Oh well, one
| can dream.
| vintagedave wrote:
| I interpreted the headline as protection against malicious
| packages. Having read the article, and being clearly not
| familiar enough with publishing on PyPi, I actually have not
| much idea what it is: maybe a different way to authenticate
| when publishing your package?
|
| Would you mind summarising in layman's terms please? And does
| this have any relevance to package manager trust and security?
| decide1000 wrote:
| I understand the focus on Github, they are the biggest. But so
| many use Gitlab, Gitea, Bitbucket, .. Would love to see some
| examples for those as well
| 2h wrote:
| I have no issue with this. HOWEVER, every single time I have ever
| seen this happen, the same situation plays out:
|
| 1. Introduce "trusted" something as an option
|
| 2. Make trusted the default
|
| 3. Make non trusted opt in, requiring explicit "OK"
|
| 4. Keep increasing difficulty of installing non trusted items
|
| 5. Make non trusted items impossible to install
|
| Please, PLEASE learn from past mistakes and stop at step 3,
| unless you actively want to ruin PyPi.
___________________________________________________________________
(page generated 2023-04-20 23:01 UTC)