Block download of components when violating policy

Hello everyone,

Following the ongoing conversation about blocking downloads of components due to policy violations, We are interested in moving this idea forward through the PEP process. I have read and familiarized myself with the steps and requirements in PEP 1 and am prepared to begin drafting a PEP on this topic.

Could anyone share advice or best practices for getting started, or any suggestions I should keep in mind as I write the initial draft? I would also appreciate any guidance on finding a sponsor or coordinating with relevant stakeholders.

To provide some context, I have opened an implementation proposal in pip to illustrate how this change could look in practice: pypa/pip#13620.

Thank you for your time and any insights you can offer as we begin this process.