-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Should https://pypi.org/project/autodoc-traits/ be under the jupyter org on Pypi ? #70
Comments
@Carreau I suppose that they should be under the Project Jupyter org (which I didn't realize was set up on PyPI until this message). I don't have strong feelings either way except for perhaps improved supply chain security. |
I guess one question I have is who retains maintainer privileges on the repo on PyPI? |
I think it should still be the same maintainer, and I suggest we do like we did for IPython (#68), and also adds the maintainer as individual maintainer, otherwise we can't see sho maintains. See IPython: https://pypi.org/project/ipython/ and unfortunately we can't see the members of the orgs : https://pypi.org/org/jupyter/ BTW, if this is something you can nudge on warehouse, I think it's weird that if you maintain a project via an org, you can't make public the fact that you are part of an org/team, that make individual maintainer loose all credit about the work they do. Like before #68 IPython was not visible in https://pypi.org/user/mbussonn/ |
Related: I just opened |
Yeah, it's a JupyterHub project so should probably be under the org |
Anyone with permission to do it ? |
Sorry, forgot about it. Moved it to the org today. |
No worries; you may want to add yourself as a maintainer back (otherwise we can't see your name), otherwise +1 to close this now. |
Yeah, I saw that. I actually don't have permission to do that. I am a "maintainer" on the org, which I guess doesn't include permission to modify contributors. |
@minrk I added you as an owner on the autodoc-traits repo, so your name appears. |
@Carreau yes, I think so. I believe the PyPI org is pretty new, so it's going to take some time to migrate stuff over. If you have bandwidth to help move repos over, that would be great! |
Also, I think we should open up the "owner" role on the PyPI org to folks on the SSC. Right now, it's only EC folks. I don't think that's enough hands to help manage this stuff 😅. |
I'm guessing one of the question is "how to we even know which packages we need to check". |
@minrk, @willingc, @consideRatio ?
In general should packages be audited to check wether they are under the pypi org ?
The text was updated successfully, but these errors were encountered: