PEP 458: Secure PyPI downloads with package signing

Of the points I raised, the following two remain outstanding with addition of the text you quoted:

  • What benefits were gained from using TUF in those organisations?
  • How do other ecosystems handle this issue (in particular, what alternatives to TUF have been used)?

but I’m not particularly inclined to make an issue out of it. If I were going to push for anything further, it would be a (brief) summary of what alternatives to TUF exist. Personally, though, I’ve probably got the context I need from the discussions here, so adding that sort of information would be only marginally useful to me, and I don’t really want to continue the debate solely on behalf of hypothetical readers who don’t have a feel for what TUF is.