4 ms·
Here’s cupy’s postmortem— https://github.com/cupy/cupy/issues/4787 https://github.com/cupy/cupy/issues/4787 Salient points being that cupy releases a new name
by CapriciousCptl 6y ago
Here’s cupy’s postmortem—
https://github.com/cupy/cupy/issues/4787 https://github.com/cupy/cupy/issues/4787
Salient points being that cupy releases a new named package for each cuda version, so future package names are of course predictable. Since PyPi doesn’t allow namespacing, cupy’s plan is to register new names ASAP when cuda releases a new version and monitor and report other packages purporting to be cupy that get uploaded.
- alisonkisk 6y agoWhy not pre-register? Why wouldn't attacker pre-register?
- SloopJon 6y agoThat's interesting. There is a policy and process (PEP 541) in place for addressing this, and it seems to have been executed swiftly and responsibly. Is this incident an argument for namespacing, or that the status quo is good enough? I feel like domain name disputes tilt disproportionately to trademark holders, so I wouldn't like to see, e.g., cupy block a cupyd package or vice versa (or, for that matter, NVIDIA somehow strongarm cupy). On the other hand, you'd like a mechanism by which you can trust that a package comes from the cupy maintainers.
- xapata 6y ago> PyPi doesn’t allow namespacing Yet. I suppose it might wind up vaporware, but the feature request is under discussion/development. BTW, it's PyPI.