| ▲ | darkamaul 2 days ago | |
One of the biggest issues I see with Upload Queues here that is not talked about is the added complexity on the package managers themselves (PyPI, NPM, crates.io ...). They are already complex beasts of software, extremely important for the ecosystems, and not always well funded. Adding all this extra complexity, with official bypasses (for security reasons), monitoring APIs (for security review while a new version is in the queue), and others is not cheap. And if somehow, they get the funding to do this, will they also get the funding for the maintenance in the long term? I don't think the benefits here (which is only explicitly model the cooldown) are enough to offset the downsides. | ||