Supply chain weirdness: So this project lost their pypi credentials & had to publish under a new pypi name. As a library user, I'd want to know that a package is the same as the code from such & such a git repo. Either by cryptographic signature or because the bits are the same.
Ref this snafu
https://github.com/zalando/connexion/releases/tag/2.10.0♡ 0 ↻ 0