Jazzband bot upload and delete access to PyPI repositories
- Dominant language
- No language data
- Stars
- 28
- Forks
- 6
- PR merge metrics
- No merged PRs in 30d
Description
The Jazzband bot needs to always have the ability to delete a release in Jazzband repositories.
The project setup could benefit from a an automated check for the access permissions.
In the case there is a security compromising or other ill willed release we might not otherwise be able to react to malicious actors fast enough.
Discussing potential takedown procedures with PyPA would make sense as well as Jazzband is vendoring dozens of relevant packages and using a lot of pull in the Django community.
Such pull tends to lead to malicious actors gaining interest in the account and organization pretty quick as well, especially with all the attack surface the high number of contributors offers.
Contributor guide
Assessment
This issue has not been assessed yet.