I'm beyond happy to see this work become the default, especially in light of the other big changes[1][2][3] to PyPI that have happened over the past few weeks. As the post says, this work <i>directly</i> makes the index as a whole safer, and does so while bringing PyPI in line with other major centers of the OSS world[4].<p>[1]: <a href="https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/" rel="nofollow">https://blog.pypi.org/posts/2023-04-20-introducing-trusted-p...</a><p>[2]: <a href="https://blog.pypi.org/posts/2023-04-23-introducing-pypi-organizations/" rel="nofollow">https://blog.pypi.org/posts/2023-04-23-introducing-pypi-orga...</a><p>[3]: <a href="https://blog.pypi.org/posts/2023-05-23-removing-pgp/" rel="nofollow">https://blog.pypi.org/posts/2023-05-23-removing-pgp/</a><p>[4]: <a href="https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/about-two-factor-authentication" rel="nofollow">https://docs.github.com/en/authentication/securing-your-acco...</a>