(original) (raw)
Ideally authors will be signing their packages (using gpg keys). Of course
how to distribute keys is an exercise left to the reader.
On Friday, June 22, 2012 at 11:48 AM, Vinay Sajip wrote:
<martin <at> v.loewis.de> writes:See above. Also notice that such signing is already implemented, as partof PEP 381.BTW, I notice that the certificate for https://pypi.python.org/ expired a weekago ...Regards,Vinay Sajip\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_Python-Dev mailing list