Earlier this year, Brett Cannon consulted with Donald and updated the status of PEP 458 to Deferred. https://github.com/python/peps/pull/931

The PEP status is now Draft again and the new proposed title is

"PEP 458: Secure transport independent download integrity for PyPI packages"

(see https://github.com/secure-systems-lab/peps/blob/c13384a4fac6822626abb7e09ab7f6143179820f/pep-0458.txt ).

Current discussion is happening on Discourse:

https://discuss.python.org/t/pep-458-surviving-a-compromise-of-pypi/2648/

--
Sumana Harihareswara
Changeset Consulting
https://changeset.nyc
--
Distutils-SIG mailing list -- distutils-sig@python.org
To unsubscribe send an email to distutils-sig-le...@python.org
https://mail.python.org/mailman3/lists/distutils-sig.python.org/
Message archived at 
https://mail.python.org/archives/list/distutils-sig@python.org/message/CICYGLMVXPNBFZVV7I33XBGCPGFYXKQC/

Reply via email to