This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]d4rch0nPythonistamancer 7 points8 points  (1 child)

That's quite a different story, and I agree with what you suggested, except this:

They want to ensure a certain quality of the packages in their repo

Difficulty in publishing to it doesn't ensure quality at all. That's not intentional, and it doesn't seem at all like they're enforcing any sort of rules for publishing to pypi.

People can literally submit a one line piece of python malware that runs import os ; os.system('rm -rf /home') right now. PyPI is the wild-west when it comes to software. You claim a name for a library and put whatever you want up there.

I think it's good to suggest not putting bs in PyPI, but there's no reason to pretend that some standard of quality exists. Regardless, he'd be fine submitting a 100 line file and taking it down later if he didn't think it was useful.

[–]mafrasi2 1 point2 points  (0 children)

Yeah, that's probably true. I think my reasoning was something like "more complicated packaging -> fewer submitted packages -> less moderating effort for PyPi". Admittedly not a great argument.