#Bit of an internal discussion that we re
1 messages · Page 1 of 1 (latest)
When we remove malware, we prohibit the entire project name. So package-a would no longer be publishable regardless of version.
Oh hey Dustin. Thanks for the reply-- that is very good to hear, we were concerned our system might be missing some packages, but it sounds like that's not possible.
Also, point of clarification on your second item: technically the filename cannot be reused, not the version: https://pypi.org/help/#file-name-reuse
Tracking, thanks for the information, and thank you for your hard work in helping us out with PyPI security ❤️