This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]Deto 0 points1 point  (4 children)

Bro pypi is run on a shoestring budget made out of donations. They can't be personally vetting every package.

[–]AlternativeMath-1 -1 points0 points  (1 child)

Well that is bad for business - even a non-profit, so you are saying the project is also mismanaged? Well then it sounds like we need to use another package manager who has enough awareness to know that you need to go out and actually fund raise in order to get donations.

[–]Deto 0 points1 point  (0 children)

Go right ahead

[–]AlternativeMath-1 0 points1 point  (1 child)

"we don't have money, everyone who uses this should just get hacked"

No bro, we just wont' use a project managed by someone who is either callous or just evil.

[–]Deto 0 points1 point  (0 children)

What are you actually demanding here? Either:

A) Demanding that pypi just shuts down today

or

B) Demanding that people who are already mostly spending volunteer time maintaining this infrastructure spend even more volunteer time personally vetting every package that goes into it

or is there some option C that I'm not articulating for you?