#pypi survey
Can this be buried any deeper?
- go to project
- go download files
- view details - Oh look, there are signatures.
Anyhow, back to my original thesis, another anonymous user who may or may not be in control of their github actions (if they didn't run zizmor, that action could literally be anyone), published that package and it came from that server.
♡ 0 ↻ 0