You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The post mentions some previous conversation with Pypi maintainers (public? private?), this issue makes this important problem visible in the issue tracker.
The possibility to register a deleted package is bad for software supply chain security, see
Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/
The post mentions some previous conversation with Pypi maintainers (public? private?), this issue makes this important problem visible in the issue tracker.
Stop Allowing deleting things from PyPI?, is related but slightly different.
The text was updated successfully, but these errors were encountered: