This is also a technical issue: As long as zc.buildout and setuptools
foolishly accept dependency links from an egg, it'll be painful to
detect accidental reliance on external repositories.

That's a good point. I wouldn't go so far as to say "foolishly", but I would say that this is a policy that should be overrideable. Checkins to buildout (with tests, of course) accepted.

Sort of that, a feature request in launchpad would be helpful so this idea doesn't get forgotten.


