Hacker News new | ask | show | jobs
by orf 2023 days ago
You didn’t identify certifi, urllib3, chardet or pytz in your top 10 critical Python dependencies. These are all highly download packages, mostly maintained by one person, which are totally critical to millions of other packages and the Python ecosystem as a whole.

A few of your top-10 I can agree with, but when you’re saying a home-automation package (“core”) is more critical than something like pytz then something has gone terribly wrong.

1 comments

Filed https://github.com/ossf/criticality_score/issues/20, we will fix this, have an idea on the issue.