> The message to me as a maintainer is quite clear: once a project achieved criticality, then the index wants to exercise a certain amount of control
I don't think that's the definition of control. Pypi gains no power with this, only more work.
And 2FA is really not a big deal.
> One could imagine that an index would like to enforce cryptographic signing of newly released packages.
Yes. Please yes.
Letsencrypt was a boon to the web.
Having a quick way to sign your package to send it so pypi would be a great thing.
This is a long article over nothing.