Draft PEP: Adding Vulnerability Data to the Simple API for Package Indexes

Trawling through the pip-audit discussion, I found this:

I had forgotten that previous discussion, and as a result raised this again here. It really isn’t a useful way to spend people’s time, expecting them to hunt out all of this context. It’s the job of the PEP to collect and summarise prior discussions and conclusions in support of the proposal (as well as prior objections, so that they can be addressed in the PEP). While I appreciate the PEP is still just a draft, I think it needs a significant amount of fleshing out before submitting it for public review.