3 ms·
> The problem described in the post isn't the fault of package naming schemes If PyPI used Java-like scheme with domain ownership verification, Google would pr
by vsl 3y ago
> The problem described in the post isn't the fault of package naming schemes
If PyPI used Java-like scheme with domain ownership verification, Google would presumably use com.google.* namespace for their private stuff and it wouldn’t be possible to introduce malicious package this way.
So the described issue arguably is a consequence of that.