HulaHoop0

Results 4 comments of HulaHoop0

pip still has no idea about code signing in this day and age. It was conisdered a big leap forward when they implemented fetching over HTTPS and reject plaintext connections...

> Cryptographicly signing packages does not prevent their authors to publich malicious packages, which happened in case of npm and pip. Right. What we want to do is ensure no...

Hi @aakselrod wondering if you have any update on this?