You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The kodiak-rure package is a direct copy of my rure package: https://pypi.org/project/rure/ . It stems from this issue on my github repo: davidblewett/rure-python#24 . The new package was uploaded solely for the purposes of distributing a binary wheel for M1 Macs. The folks that uploaded it didn't wait for my response on providing a binary wheel. Since this wheel contains a binary (originally intended for wrapping the Rust regex crate), it is possible that the uploaded wheels have malicious content in them. I asked them to remove the package to avoid confusion with the canonical repo almost a week ago, but haven't had a response since.
I have not had time to maintain the original rure package, but I would prefer an orderly transfer of it to someone rather than it being hijacked.
Hi @davidblewett, I don't think PEP 541 covers this scenario as its primary use case is the transfer of abandoned projects.
That being said I will try to communicate with @chdsbd to see if he'd be willing to remove the project and/or contribute to rure to include the extra binary wheels.
Project to be claimed
kodiak-rure
: https://pypi.org/project/kodiak-rureYour PyPI username
davidblewett
: https://pypi.org/user/davidblewettReasons for the request
The
kodiak-rure
package is a direct copy of myrure
package: https://pypi.org/project/rure/ . It stems from this issue on my github repo: davidblewett/rure-python#24 . The new package was uploaded solely for the purposes of distributing a binary wheel for M1 Macs. The folks that uploaded it didn't wait for my response on providing a binary wheel. Since this wheel contains a binary (originally intended for wrapping the Rust regex crate), it is possible that the uploaded wheels have malicious content in them. I asked them to remove the package to avoid confusion with the canonical repo almost a week ago, but haven't had a response since.I have not had time to maintain the original
rure
package, but I would prefer an orderly transfer of it to someone rather than it being hijacked.Maintenance or replacement?
Replacement
Source code repositories URLs
https://github.com/davidblewett/rure-python
Contact and additional research
I asked for the package to be removed on June 29, 2022: davidblewett/rure-python#24 (comment) .
Code of Conduct
The text was updated successfully, but these errors were encountered: