Comment by firesteelrain
9 hours ago
This seems like common sense configuration management 101. If I download v1.2 and it’s been published then it should be considered released and not modifiable. With exceptions for ‘dev’ releases of course. I have never published anything on PyPI but I would expect there is a publish button and finalize (?) optional button that if not checked after 14 days makes it final ?
Are there any package managers that have that kind of publish/finalize flow?
Every one I’m aware of works either as a one-shot (you have to submit everything in one push) or lets you keep adding new assets forever (other, obviously, than PyPI with the addition of this 14 day wall).
In the Java world, Maven has a "publish" step. Published artifacts (groups of files) are immutable, so publish == finalize.
That’s exactly how individual artifacts are (and were) on PyPI. This change isn’t to artifact immutability, it’s to releases (collections of artifacts)
2 replies →
Doesn’t that sound bizarre? I have never heard of such a thing. The builds should be immutable
No?
Again, can you think of any packages managers that have a finalize step like you’re describing?
All the package managers I’m aware of do one of two things:
1. You push once with everything baked in.
2. You push as many things as you want forever.
Python releases can sometimes have many different package files (for example, because each platform can have its own wheel), which makes the first option pretty challenging.
3 replies →