|
|
|
|
|
by Wowfunhappy
1438 days ago
|
|
> PyPI offered to provide a security key to make the maintainer's life easier It's even easier to just leave 2FA disabled and stop maintaining the project. Which is what they did. Are maintainers obligated to support their projects indefinitely? |
|
I recently ran into a situation where a very old package caused terrible damage.
I contacted the pypi maintainer. He apologized and promised to fix it. Six months later, no changes.
This was a very unusual situation, as the package was the same name as a module later adopted in the standard library.
The author was under the impression the package was literally uninstallable since the code hadn’t been valid Python for over two decades, including the setup script.
Still wish they would delete it.