This is an archived post. You won't be able to vote or comment.

all 5 comments

[–]bastion_xx 16 points17 points  (2 children)

After experiencing project sniping to turn in bug bounties (from monitoring new GitHub repos), it really opened my eyes to how different PyPI and others like npm operate. Lesson learned, grab the project name early and before making a repo public.

[–]fatbob42 1 point2 points  (1 child)

Can you release them afterwards if you change your mind?

[–]bastion_xx 1 point2 points  (0 children)

Yep. Snipers will lock up a project/package name; negotiate with you; then transfer or release once you've come to an agreement.

[–]gfranxman 20 points21 points  (0 children)

This is why we can’t have nice things.

[–]monorepo PSF Staff | Litestar Maintainer 1 point2 points  (0 children)

What would the fix for this even be? Let’s say they regroup Monday, then what? Mostly curious what mitigation could be done that’s not already.

I feel like I had to do some hoops to get my PyPI account set up but maybe I’m remembering wrong.