packaging

packaging

Posts about the Python packaging ecosystem.

Why pylock.toml includes digital attestations

A Python project got hacked where malicious releases were directly uploaded to PyPI. I said on Mastodon that had the project used trusted publishing with digital attestations, then people using a pylock.toml

© 2013 Brett Cannon