New T&C: Is PyPI moving towards a paid subscription model and/or abandoning package neutrality?

(I am not a lawyer, this is my personal opinion, etc.)

This didn’t sound right to me, so I checked: the AUP going back at least to June 2024 (archive.org link) includes the following language:

PyPI retains full discretion to take action in response to a violation of these policies, including account suspension, account termination, or removal of content.

While the majority of interactions between individuals in PyPI’s community fall within our Acceptable Use Policies and Community Guidelines, violations of those policies do occur at times. When they do, PyPI staff may need to take enforcement action to address the violations. In all cases, these actions are permanent and there is no basis to reverse a moderation action taken by PyPI Staff.

My interpretation of the new T&C is that they’re a more idiomatic (in terms of legalese) way of saying the same thing the old AUP said. So I think it’s incorrect to describe a change in policy around neutrality here: you might disagree with the old policy too, but I would argue that it’s morally identical to the new one in terms of powers granted to PSF/PyPI.

All told, I don’t agree that the character of PyPI has been meaningfully altered by these terms. PyPI continues to be an uncurated index, but that doesn’t mean (and has never meant) that the index is “fair game” for spam, malware, or personal file hosting (or just about anything else that would pose a risk to PyPI’s role in the ecosystem).

9 Likes