Comment by nneonneo
6 hours ago
The remaining risk now is that a patient, malicious actor could put out a new, clean source-only release, wait for ~7 days for people to decide it's safe and update to that version (and pass typical update delay controls), and then attach a bunch of malicious binary wheels. 14 days still seems to be too long.
Of course, this is already miles better than the current state of affairs where an old but popular package could become an infection vector at any time.
No comments yet
Contribute on Hacker News ↗