3 ms·
I think the reason here is to prevent deletion that cause upstream disruptions. See the reasoning in the PEP 763 (not adopted ) https://peps.python.org/pep-07
by darkamaul 11mo ago
I think the reason here is to prevent deletion that cause upstream disruptions.
See the reasoning in the PEP 763 (not adopted )
https://peps.python.org/pep-0763/ https://peps.python.org/pep-0763/
- eviks 11mo agoStrange they haven't identified negative security implications: if the owner notices the hack he can delete the malicious release before the central authority, so this would limit the blast radius (think there was a recent such issue with npm where there was a delay between discovery (by the author) and removal) Otherwise yes, leftpad/coverup risk is a thing