Hi! I'm forwarding this on behalf of Marina Moore https://github.com/mnm678 .

- Sumana Harihareswara
---


PEP 458 ( https://www.python.org/dev/peps/pep-0458/ ) proposes using The Update 
Framework (TUF) to allow users of PyPI to verify that the packages they install 
originate from PyPI. Implementing this PEP would provide protection in the 
event of an attack on PyPI, its mirrors, or the network used to install 
packages.

We started this PEP in 2013, and have recently revised it and restarted 
discussion.

Recent discussion and revision of the PEP has been taking place on Discourse ( 
https://discuss.python.org/t/pep-458-secure-pypi-downloads-with-package-signing/2648/44
 ).

The PEP is ready for review and I look forward to your feedback!

Thanks,
Marina Moore
PEP 458 coauthor
_______________________________________________
Python-Dev mailing list -- python-dev@python.org
To unsubscribe send an email to python-dev-le...@python.org
https://mail.python.org/mailman3/lists/python-dev.python.org/
Message archived at 
https://mail.python.org/archives/list/python-dev@python.org/message/ARJLCFBZJYTDXHRMK6YP5SNAHD34HNR5/
Code of Conduct: http://python.org/psf/codeofconduct/

Reply via email to