help icon indicating copy to clipboard operation
help copied to clipboard

Jazzband bot upload and delete access to PyPI repositories

Open aleksihakli opened this issue 6 years ago • 0 comments

The Jazzband bot needs to always have the ability to delete a release in Jazzband repositories.

The project setup could benefit from a an automated check for the access permissions.

In the case there is a security compromising or other ill willed release we might not otherwise be able to react to malicious actors fast enough.

Discussing potential takedown procedures with PyPA would make sense as well as Jazzband is vendoring dozens of relevant packages and using a lot of pull in the Django community.

Such pull tends to lead to malicious actors gaining interest in the account and organization pretty quick as well, especially with all the attack surface the high number of contributors offers.

aleksihakli avatar Aug 30 '19 12:08 aleksihakli