|
|
|
|
|
by woodruffw
588 days ago
|
|
> Absence of support for self-hosting, or for that matter for any non-proprietary service? This has nothing to do with self-hosting, whatsoever. You can upload to PyPI with an API token; that will always work and will not do anything related to Trusted Publishing, which exists entirely because it makes sense for large services. PyPI isn't required to federate with the server in my basement through OpenID Connect to be considered open source. |
|
And maybe that's a good thing? I'm not against security, and supply chain attacks are real. But it's still kind of sad that the amazing machines we all own are more and more just portals to the 'trusted' corporate clouds. And I think there are things that could be done to improve security with local uploads, but all the effort seems to go into the cloud path.