5 ms·
This is a pretty sad state of affairs. * There is no namespaces, so all internal packages must be individually protected * It's easy to misconfigure the variou
by capitol_ 3y ago
This is a pretty sad state of affairs.
* There is no namespaces, so all internal packages must be individually protected
* It's easy to misconfigure the various python package tools to open you up to dependency confusion attacks
* The only effective protection mechanism that you can implement across a large enterprise fills the index with spam and is forbidden
It would really improve things if they could introduce namespaces and let legal entities own those.
- mananaysiempre 3y agoYeah, this sucks, and I won’t claim that a sudden crackdown on invalid packages would help the situation, nor that eliminating that rule would. Namespaces could probably help some. However, while I don’t know how the PSF folks feel, if it were up to me, when it came to the “let legal entities own those” step I’d throw my hands up and point people to the DNS namespace, the way Go, Nix, etc. do. That’s not a perfect solution, but so far that DNS is the namespace with mainstream acceptance and builtin lawyers that a single entity cannot e.g. just singlehandedly sanction, sue or simply “reserve the right to refuse” people out of—in practice, for the most part. PyPI’s (and CPAN’s, CTAN’s, Hackage’s, NPM’s) centralized index was originally a (deliberately) crude solution to the discoverability problem, at least in part. These days, we have adopted a different bad solution—putting everything on a Microsoft-owned hosting service with a crap search function. That is also quite bad, but maybe it’s time we recognize it happened anyway and stop making concessions to the old solutions in our package naming schemes.