TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Is PyPI moving towards a subscription model or abandoning package neutrality?

3 点作者 BerislavLopac2 个月前

1 comment

eesmith2 个月前
This is an inference based on a change in legal terms. No resolution yet if it reflects any deeper intent. (I suspect it&#x27;s made by lawyers who default to &#x27;make sure we control everything&#x27; when they write their terms, like every other corporate ToS we all supposedly agree to willingly.)<p>Still, I&#x27;ve seen that PyPI costs a lot to run, and just like ReadTheDocs I expect that a future PyPI will need a bigger income stream somehow.<p>I also well remember that PyPI mandated 2FA even for those who didn&#x27;t want to switch, which is an ever-present reminder that they control distribution.<p>I stopped distributing on PyPI years ago, in favor of my own &quot;simple index&quot; package distribution.<p>I wish pip etc. had a good mechanism already for mitigating dependency confusion. I can see that people who download my package also try downloading other packages, like pybind11, from my index, even though it isn&#x27;t even a dependency of mine.
评论 #43257750 未加载