3 ms·
So just yesterday PyPI announced they're retiring cryptographic signatures: https://news.ycombinator.com/item?id=36044543 https://news.ycombinator.com/item?id=3
by throw_a_grenade 3y ago
So just yesterday PyPI announced they're retiring cryptographic signatures: https://news.ycombinator.com/item?id=36044543 https://news.ycombinator.com/item?id=36044543.
It's hard to keep those things separated. I would very much like the code submitted to PyPI be protected end-to-end by cryptographic signatures, when PyPI has either no resources, or no spine to stand up to a government. Any signatures, even PGP, which should be in place until someone provides better mechanism.