I am fully onboard with just using 694s protocols here in terms of the control plane.
I do not think this needs to be completed through the webUI for every release. I think the primary separation I want to see here is that separating out those two roles to provide some security in layers such that if one or the other role has compromised credentials then it still makes it much harder to get malware through the process.
This really only differs because I was trying to find a way that says we wont block forever if a security scanner does not come back. So I would read the timeout here as only applying to automated scanners. I was treating no signal after a given window as a positive signal instead of a negative signal.
I was more thinking more that PyPi would share stage tokens with trusted security partners. I like the embargo functionality of 694. It fits in with what I am trying to achieve here which is providing a bit more proactive security in layers.
I am more than happy to have this end up as mostly amendments to 694 if we think that is the right path forward. Or still happy to write a separate PEP here for the legacy API portions.