[Distutils] PEP 458: Surviving a Compromise of PyPI: Round 1

Donald Stufft donald at stufft.io
Sat Nov 23 16:23:14 CET 2013


They are signed. Just not by an author key. 

> On Nov 23, 2013, at 9:58 AM, Paul Moore <p.f.moore at gmail.com> wrote:
> 
> "Unsigned" is accurate and specific - "unclaimed"
> sounds like I don't care about my project.


More information about the Distutils-SIG mailing list