2FA means we can trust the person that logged in - but we still don't trust that PyPI is being honest (no offense).
2FA means we can trust the person that logged in - but we still don't trust that PyPI is being honest (no offense).
PEP 458 describes the path forward for PyPI. https://peps.python.org/pep-0458/
Here's the in-progress roadmap: https://github.com/pypi/warehouse/issues/10672
If there's particular issues you believe you could pick off to help achieve the goal, much appreciated!
That is covered by PEP 480, which is already 9 years old:
https://peps.python.org/pep-0480/
Too bad that PyPI (and pip) effectively killed PGP signatures under control of the developers (therefore truly end to end) even with the simple TOFU model, and without providing an alternative.
PyPI never supported "signed builds" in the first place. What it had was vestigial support for attaching PGP signatures to distributions; without a key or identity distribution mechanism, these signatures were virtually useless (and all public evidence indicates that they were, consequently, virtually unused).
Note that attached signatures alone don't prevent dishonesty on PyPI's part: without identity pinning, a dishonest PyPI could replace a correctly signed distribution Foo with a correctly signed (and easily exploitable) distribution Bar during a user's retrieval. Every signature needs to be bound to both the distribution's content and its distribution name by some stable discoverable identity.