Survey on improving the #pypi sidebar today.
I told them I think "verified / Trusted Publisher" means, "the build server used a short lived password"
(thinking more, if metadata is signed but nothing else is, what a weird place to stop. Like, ooh, I trust this metadata, so I trust the unsigned #python wheel?)
We don't know who publishes ANYTHING to pypi.org it is all anonymous. "That build server" isn't exactly what people mean by identity. Sure, it narrows it down.
I fork packages and I don't want to look like I taking credit away from the original author, so I leave their names there. But the UI now makes it look like my published package is somehow *them*. That trust should not extend to my package. People should only trust it if they trust me. Ditto for the 150 contributors who didn't publish the package. (I mean, except if we skip blaming the publisher and blame the person who snuck in a malicious commit)
♡ 2 ↻ 0Don't get me wrong, I'm happy they're thinking about this & and doing the survey.
♡ 2 ↻ 0