[Distutils] Migrating Hashes from MD5 to SHA256

Antoine Pitrou solipsis at pitrou.net
Sat Jul 27 19:25:51 CEST 2013

Donald Stufft <donald <at> stufft.io> writes:
> On Jul 27, 2013, at 7:12 AM, Antoine Pitrou <solipsis <at> pitrou.net> wrote:
> > Donald Stufft <donald <at> stufft.io> writes:
> >> Most people will use the setuptools bundled with virtualenv which has
> >> only ever bundled 0.6 or 0.9.
> > 
> > Why do you think that? According to PyPI:
> > - virtualenv:
> > 4664 downloads in the last day
> > 34512 downloads in the last week
> > - setuptools:
> > 23901 downloads in the last day
> > 197351 downloads in the last week
> > 
> > Certainly setuptools use seems much more widespread than virtualenv use.
> > 
> > Regards
> > 
> > Antoine.
> > 
> Comparing download numbers isn't generally useful. People
> almost never install virtualenv more than once per machine. There
> are a myriad of reasons why they might directly install setuptools.

If your assertion were true ("Most people will use the setuptools
bundled with virtualenv"), then the setuptools download numbers
would be minuscule. The actual numbers show it to be untrue.
Whether or not they are directly comparable isn't important: the
orders are magnitude are sufficiently eloquent.

> It's impossible to know for sure how it'll be gotten but my gut is
> that most people use whatever is default inside of virtualenv
> because that's how almost everyone i've seen who uses virtualenv
> does it unless they have special needs.

Perhaps you don't realize that many people don't use virtualenv at all,
so they simply cannot use virtualenv's setuptools, either. Which is
perfectly compatible with those download numbers, unlike your original



More information about the Distutils-SIG mailing list