Establish publisher authority via automated DNS backed challenges?

I was wondering about this throughout the other discussions. It seems like a third-party package index is a better option than namespaces on PyPI[1]. I was confused about why that wasn’t being discussed so much in the namespace threads.

It seems like the answer is: because third-party indexes are already sorta-supported and used, but not sufficiently well-supported to solve the problem for many organizations. So solving this first makes a lot of sense to me, before other solutions are required.


  1. simpler for an organization to administer, the namespace isn’t crowded, they don’t build tiers into PyPI, and more ↩︎

4 Likes