Live data from Hacker News

Viewing profile — di

di

HN member
Joined
Wed, Nov 30, 2011, 2:00 AM UTC
HN karma
1,555
Public activity
175 items

About di

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. story
  4. comment
    Comment #46035157

    Maven Central does not currently support OIDC-based authentication (commonly called "Trusted Publishing").

  5. comment
    Comment #45722520

    For some context on the scale of this grant, the PSF took in only $1M in "Contributions, Membership Dues, & Grants" in 2024: https://www.python.org/psf/annual-report/2024/

  6. comment
    Comment #45722473

    It says "September 23, 2025" right at the top.

  7. comment
    Comment #45531453

    Don't be embarrassed, it's a good book (and was my favorite too).

  8. story
  9. comment
    Comment #45211809

    Note that https://peps.python.org/pep-0440/#direct-references says: > Public index servers SHOULD NOT allow the use of direct references in uploaded distributions. Direct reference…

  10. story
  11. story
  12. story
  13. story
  14. story
  15. comment
    Comment #37062385

    This is why PyPI recommends using Trusted Publishing ( https://docs.pypi.org/trusted-publishers/ ) which removes the need for long-lived tokens entirely.

  16. story
  17. story
  18. comment
    Comment #36351071

    That article is about the packaging summit talk on introducing namespaces, not about organizations. In fact, when talking about organizations, it explicitly says: > But support for…

  19. comment
    Comment #36346313

    > An example of this is that PyPI just got the ability to namespace packages. You're thinking of organizations, which are not namespaces: https://blog.pypi.org/posts/2023-04-23-int…

  20. comment
    Comment #36327027

    Pip supports checksums too. A better link might be https://pip.pypa.io/en/stable/topics/secure-installs/

  21. comment
    Comment #36081901

    PyPI has never supported 2FA via SMS.

  22. comment
  23. comment
    Comment #35902601

    Periods are not prohibited in package names, they're just uncommon (e.g., https://pypi.org/project/zope.sqlalchemy/ )

  24. comment
    Comment #35648416

    Gitlab also doesn't support customizable OIDC audiences yet: https://gitlab.com/groups/gitlab-org/-/epics/7335

  25. story