2 ms·
I suspect your discounting the amount of effort it takes pypi index maintainers to respond to compromised packages. In the same way folks can get upset over be
by jayofdoom 4y ago
I suspect your discounting the amount of effort it takes pypi index maintainers to respond to compromised packages.
In the same way folks can get upset over being required to use 2fa, the package index maintainers likely get upset every time that they lose hours of their life due to someone not using 2fa.
Despite much of this being critical infrastructure, I would be surprised if most people who run the index are doing so as part of their day job instead of volunteering. This is why I always try to show a lot of grace when people make decisions that I don't understand, because they may be facing situations I don't understand.