← Back to context

Comment by akerl_

6 hours ago

Are there any package managers that have that kind of publish/finalize flow?

Every one I’m aware of works either as a one-shot (you have to submit everything in one push) or lets you keep adding new assets forever (other, obviously, than PyPI with the addition of this 14 day wall).

Doesn’t that sound bizarre? I have never heard of such a thing. The builds should be immutable

  • No?

    Again, can you think of any packages managers that have a finalize step like you’re describing?

    All the package managers I’m aware of do one of two things:

    1. You push once with everything baked in.

    2. You push as many things as you want forever.

    Python releases can sometimes have many different package files (for example, because each platform can have its own wheel), which makes the first option pretty challenging.

    • My point is adding stuff to an existing version doesn’t make it immutable like it should such as Maven-style

    • I'm learning here, but for option 2, besides the security risk, doesn't this create the possibility that users could get a broken/unfinished package any time they're updating to a recently "published" release? The property of releases being atomic seems very important.

      1 reply →

In the Java world, Maven has a "publish" step. Published artifacts (groups of files) are immutable, so publish == finalize.

  • That’s exactly how individual artifacts are (and were) on PyPI. This change isn’t to artifact immutability, it’s to releases (collections of artifacts)

    • Yeah, I think that's the difference. In Maven, the entire set of files which compose a release is immutable. You can't add to or remove from the set of files once you've published. You have to release a new version if you want to add anything.

      1 reply →