3 ms·
1. Yes absolutely. I tried to not talk about specific signing implementations because this was mostly about that simply signing isn't enough, you need a trust m
by donaldstufft 13y ago
1. Yes absolutely. I tried to not talk about specific signing implementations because this was mostly about that simply signing isn't enough, you need a trust model.
2. I'm actually a PyPI admin, a pip core developer, and one of the folks working in the python packaging space. This sort of heuristics is something I absolutely want to add. Right now I'm mostly focused on closing huge gaps in security wise (prior to 1.3.x pip downloaded everything over HTTP, PyPI did not have a trusted SSL cert, etc). But Yes! Making it easier for eyeballs is a good thing.