Hacker News new | ask | show | jobs
by cpburns2009 3085 days ago
PyPI (which is what Pip uses) at the very least does not require authors to sign their packages. I can't say whether it supports signing though.