Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Moving away from distutils-sig #10928

Open
pradyunsg opened this issue Feb 28, 2022 · 5 comments
Open

Moving away from distutils-sig #10928

pradyunsg opened this issue Feb 28, 2022 · 5 comments
Labels
type: maintenance Related to Development and Maintenance Processes

Comments

@pradyunsg
Copy link
Member

Our metadata still says points to distutils-sig.

The mailing list, however, has been shut down: https://mail.python.org/mailman3/lists/distutils-sig.python.org/

Should we update this, and to what?

@pradyunsg pradyunsg added the type: maintenance Related to Development and Maintenance Processes label Feb 28, 2022
@pradyunsg
Copy link
Member Author

Should we update this, and to what?

@pypa/pip-committers This is an open question. I'm leaning toward removing this entirely. :)

@pfmoore
Copy link
Member

pfmoore commented Apr 8, 2022

Works for me. I assume you mean removing the "author email" metadata? Maybe we could add an "Issue Tracker" project URL, just to give people at least one bit of "how to contact us" metadata?

@pradyunsg
Copy link
Member Author

Maybe we could add an "Issue Tracker" project URL, just to give people at least one bit of "how to contact us" metadata?

That should be getting auto-populated with PyPI's automation for this, using the Project URL that's provided with a GitHub link. If not, that's a bug on PyPI's end.

I assume you mean removing the "author email" metadata?

Yes.

@uranusjr
Copy link
Member

uranusjr commented Apr 8, 2022

Does PyPA has a email for say security sensitive reports? I remember someone asked me about it and we didn’t have something like that. Maybe we should set up something to use in most PyPA projects, and also list it on pypa.io for people for non-public reports.

@pradyunsg
Copy link
Member Author

We just piggy-back off the security@python.org for this stuff right now -- https://www.python.org/dev/security/.

I think we can add a dedicated page for this to pip's documentation. Whether we want to do the same for other PyPA projects is a can of worms I'm not interested in touching.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: maintenance Related to Development and Maintenance Processes
Projects
None yet
Development

No branches or pull requests

3 participants