[Distutils] PEP453 - Explicit bootstrapping of pip in Pythoninstallations

Anders J. Munch ajm at flonidan.dk
Tue Sep 3 14:33:40 CEST 2013


Donald Stufft
>It also proposes that
> the distributions of Python available via Python.org will automatically run
> this explicit bootstrapping method and a recommendation to third party
> redistributors of Python to also provide pip by default (in a way
> reasonable for their distributions).

Before getpip executes code it just downloaded from the 'net, how is
it validated?  Would getpip contain the public keys of select
maintainers to verify the download?

regards, Anders



More information about the Distutils-SIG mailing list