[HN Gopher] PyPI Introduces "Trusted Publishers"
       ___________________________________________________________________
        
       PyPI Introduces "Trusted Publishers"
        
       Author : BerislavLopac
       Score  : 20 points
       Date   : 2023-04-20 21:14 UTC (1 hours ago)
        
 (HTM) web link (blog.pypi.org)
 (TXT) w3m dump (blog.pypi.org)
        
       | woodruffw wrote:
       | I'm one of the people who helped design and build this
       | functionality; happy to answer any questions about it!
        
         | morkalork wrote:
         | When I first read the title I was hoping for something like "we
         | have added a layer of curation and verification to pypi in
         | response to malicious packages being published". Oh well, one
         | can dream.
        
         | vintagedave wrote:
         | I interpreted the headline as protection against malicious
         | packages. Having read the article, and being clearly not
         | familiar enough with publishing on PyPi, I actually have not
         | much idea what it is: maybe a different way to authenticate
         | when publishing your package?
         | 
         | Would you mind summarising in layman's terms please? And does
         | this have any relevance to package manager trust and security?
        
       | decide1000 wrote:
       | I understand the focus on Github, they are the biggest. But so
       | many use Gitlab, Gitea, Bitbucket, .. Would love to see some
       | examples for those as well
        
       | 2h wrote:
       | I have no issue with this. HOWEVER, every single time I have ever
       | seen this happen, the same situation plays out:
       | 
       | 1. Introduce "trusted" something as an option
       | 
       | 2. Make trusted the default
       | 
       | 3. Make non trusted opt in, requiring explicit "OK"
       | 
       | 4. Keep increasing difficulty of installing non trusted items
       | 
       | 5. Make non trusted items impossible to install
       | 
       | Please, PLEASE learn from past mistakes and stop at step 3,
       | unless you actively want to ruin PyPi.
        
       ___________________________________________________________________
       (page generated 2023-04-20 23:01 UTC)