Proposal: Withdraw/reject PEP 708 (Extending the Repository API to Mitigate Dependency Confusion Attacks) due to lack of adoption

See my follow-up post:

That week has now more or less passed, and I have some time available, so I’m going to formally declare PEP 708 as Rejected (thanks to @hugovk for pointing out that I reject PEPs, it’s the authors that withdraw them).

Thanks to everyone who worked on the PEP, both on the the PEP itself and on the implementation work that did get done. I’m sorry that work ended up being discarded, but I do think that as a community we have learned something from the process.

Edit: Reject PEP 708 by pfmoore · Pull Request #4922 · python/peps · GitHub

10 Likes