logoalt Hacker News

8n4vidtmkvmkyesterday at 5:48 PM1 replyview on HN

I don't know how it would. Hackers would just claim everything is a security update.

Unless maybe you give special permission to some trusted company to designate certain releases of packages they don't own are security patches... But that sounds untenable.


Replies

cozzydtoday at 1:01 AM

It would have to be handled by the repository owner(e.g. PyPI) similar to how quarantines are done.