logoalt Hacker News

brewmarchetoday at 5:14 PM0 repliesview on HN

For the attack you mentioned (reusing internal packages in a public repository) prefix reservation is one possible solution. Unfortunately PyPI does not support it.