#PSRT and pip
1 messages · Page 1 of 1 (latest)
Hi William, I talked about this on the channel some time ago, I feel it may be time to split pip out of the PSRT. I think it would simplify this issue, since we generally end up delegating most work to the pip maintainers anyway.
that sounds like it could help! i'm very open to helping coordinate this however would be useful; my main interest is in ensuring that pip and uv are fully synced on reports so pip never gets sandbagged by us 😅
I suppose if it were separate, it would be easier to include more people, like trusted maintainers of uv etc.
Should such medium be expanded to other projects like Poetry, PDM and installer? We all share the vulnerability scope
Hey, I'm at PyCon US and can talk about this in person if you like. Generally pip maintainers have t been on the PSRT, but I did just join
I’m afraid I’m not there. Also, another little reason I’ve been thinking of separation, with PEP 811 the SC oversees the PSRT, however pip is beyond its scope so it’s a little confusing there.
Yeah, it's always been an informal relationship due to pip being independent but bundled into the official CPython installer
Yep, but note that's unique to pip, we don't do the same for libexpat, mpdecimal, zlib etc,
Right, there's a special history because of the relationship between Python and Python packaging and the overlap of software and people there that doesn't exist for any of those other libraries
I'm happy to start the talk of a more formal relationship or decoupling, but it's something we need to do with consensus on all sides
yeah, i think it probably makes sense to have some kind of small group for the various installers / packaging tools
i'm happy to talk about it IRL! let me know vaguely when/where you'll be and i'll try and find you 🙂
I'm heading over to Long Beach shortly, I'll be available in about 2 hours, I don't have too many concrete plans right now
That took longer than I expected but I'm now arrived and registered if you're around at all @lucid sphinx
Yep! I’m in the typing summit at the moment but will be free around 4:30
Sorry, took a bit longer to get out. I’m free now!
I'm in the main entrance area wearing a salmon t shirt
Hey folks, just saw this thread. I do think this would be a beneficial move, especially if it's paired with bringing together more maintainers from packaging tools/libraries too. Happy to help here where I can! 🙂
I’ll open a thread on Discourse.