← Back to context

Comment by woodruffw

1 year ago

That's correct!

PyPI's support for PGP is very old -- it's hard to get an exact date, but I think it's been around since the very earliest versions of the index (well before it was a storing index like it is now). If I had to guess (speculate wildly), my guess would be that the original implementation was done with a healthy SKS network and strong set in mind -- without those things, PGP's already weak identity primitives are more or less nonexistent with just signatures.

GPG ASC upload support was quietly added later IIRC. EWDurbin might recall