Comment by LtWorf
2 months ago
Download counters are completely useless. I could download your package 2 million times in under a minute and cause you to need the 2FA.
And true 2FA means you can't automate publishing from github's CI. Python is going the other direction. There is a fake 2FA that is just used to generate tokens and there is a preferential channel to upload to pypi via github's CI.
But in my opinion none of this helps with security. But it does help to de-anonymise the developers, which is probably what they really want to do, without caring if those developers get hacked and someone else uses their identity to do uploads.
No comments yet
Contribute on Hacker News ↗