4 ms·
Perhaps a good way forward is to come up with a positive incentives, like already exists with the various badges for CI success, test coverage, documentation, v
by david_draco 3y ago
Perhaps a good way forward is to come up with a positive incentives, like already exists with the various badges for CI success, test coverage, documentation, valid HTML5, etc. There could be a service that verifies that PGP key can be fetched and the latest pypi version verified. To avoid putting the burden of hosting on you, perhaps you could provide a python script which takes the package name and allows people to self-validate?
- woodruffw 3y agoPositive incentives are a good idea, and PyPI is almost certainly going to apply them to a better code signing solution than PGP.