PyTorch and the PyPI supply chain
PyTorch and the PyPI supply chain
Posted Jan 12, 2023 6:55 UTC (Thu) by bof (subscriber, #110741)Parent article: PyTorch and the PyPI supply chain
What I do not understand, from a sysadmin perspective used to the distro model, is this:
All these language package repo things, run wide open to everyone uploading stuff. With the obvious downsides. So why isn't there trusted language "distros" with trusted groups of maintainers curating that into trustable, separate repos meant for the "consumers" out there? And why the frell does everybody consuming the packaging, accept that as God given (adding in a snide remark about the Dino distros)?