Hacker News new | ask | show | jobs
by ihnorton 1613 days ago
This breaks any python package versions that install dependencies via ‘pip install’ from a pinned git+git URL. (For example: google-cloud-cpp 1.23, which was released about a year ago).
1 comments

Then the brownout had its desired effect.

Using unauthenticated transports for code is borderline malicious.