On Fri, May 31, 2013 at 4:45 PM, Trishank Karthik Kuppusamy
<t...@students.poly.edu> wrote:
> On Fri 31 May 2013 04:34:43 PM EDT, Tres Seaver wrote:
>>
>>
>> Why all the extras:  if somebody wants to claim a project name, but can't
>> upload a release for six months, they should just lose.  I would actually
>> be willing to have that cut down to a day:  trying to grab the name
>> before registering / uploading a release should result in loss of the
>> claim.
>>
>
> Firstly, let me say that the general idea sounds good, and should serve to
> improve PyPI security. However, it needs to be done carefully. Certainly
> Holger's idea of looking at how other programming language communities have
> done it is a good one.
>
> A potential problem with the "no new package in six months" heuristic is
> that it would punish mature packages with little or no improvements left.
> Would one defeat this rule by simply uploading a "new" package every six
> months?

I think Tres was referring to the first release.

Jim

-- 
Jim Fulton
http://www.linkedin.com/in/jimfulton
_______________________________________________
Distutils-SIG maillist  -  Distutils-SIG@python.org
http://mail.python.org/mailman/listinfo/distutils-sig

Reply via email to