URL: https://github.com/freeipa/freeipa/pull/379
Title: #379: Packaging: Add placeholder and IPA commands packages

tiran commented:
"""
The ```ipa``` and ```freeipa``` packages are necessary to prevent typo 
squatting or name squatting attacks, e.g. 
http://arstechnica.com/security/2016/06/college-student-schools-govs-and-mils-on-perils-of-arbitrary-code-execution/
 . We want to make sure that a developer gets FreeIPA when he does ```pip 
install freeipa```.

I already reserved the names on PyPI. It is necessary to upload new packages 
for ```ipa``` and ```freeipa``` regularly. Otherwise PyPI considers our 
packages obsolete and may remove them. See 
https://www.python.org/dev/peps/pep-0541/
"""

See the full comment at 
https://github.com/freeipa/freeipa/pull/379#issuecomment-274478485
-- 
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Reply via email to