Just finished that #python packaging survey. What I'd like is a front runner package reputation scanner that will refuse to install a package that has <1000 downloads, was published <1 week ago, has problematic CVEs. I don't like the idea of installing all the packages and then, days later, on a build server, checking to see if they're malicious.
Post
June 3, 2025