What do we want? Pip installs by hashes and verified signatures! When do we want them?
Well, code signing is hard, we shouldn't try. (that's like pypi's official stand on signatures) https://x.com/hmemcpy/status/1359478493386592267
Post
February 10, 2021