SO question I just posted, how do we stop pypi supply chain attacks?
https://stackoverflow.com/questions/66410976/how-do-i-specify-the-repository-for-all-python-dependencies
Someone is going to say hashing, but that is one burdensome pinning policy. I don't see people doing it util the tools make it easy (or if I learn that it is easier than it looks)
Post
February 28, 2021