Page MenuHome GnuPG

PyPI GPG package
Open, LowPublic

Description

Currently, there is an outdated version of Python gpgme package published to PyPI from 2018. https://pypi.org/project/gpg/

I am currently working on a refresh of a Assuan Python library: https://github.com/pygpg/pyassuan

Currently, this package is owned by Justus Winter which is a former member of GnuPG but is now part of Sequoia.

I'd like to have ownership of this package transferred to me since it is defunct at this point.

@justus
@werner

Thanks,
Jesse

Event Timeline

kuwv created this object in space S1 Public.

I'm happy to hand over the PyPI package. Werner, what should I do with it?

Thanks @justus.

@werner Full disclosure, it is possible to package gpg/gpgme within binary wheel for Python to support multiple platforms now. But, if there are no plans for that then I can use this for a namespace package instead.

https://pythonwheels.com/
https://pypi.org/project/cibuildwheel/
https://packaging.python.org/en/latest/guides/packaging-namespace-packages/

I do not consider the whole PyPi thing a secure solution and thus we do not want to engage us there. However, if you need small patches to GPGME, please go ahead post them to the ML or upload them here.

@justus: Please talk to @kuwv on how to transfer the package to him.

@justus: Please talk to @kuwv on how to transfer the package to him.

Sure thing.

But, I'm having trouble with my mails not getting through to the GnuPG devel mailing list lately. In particular, the mail from Thu, 22 Dec 2022 13:01:08 +0100 with the message id <87cz8bwsu3.fsf@europ.lan> went missing. Maybe you can have a look?

No more logs. My understaning is that the pypi ownershipof the project has been transferred to @bernhard

werner removed a subscriber: werner.

Yes I am an admin on the https://pypi.org/project/gpg/ package.

@werner let me know if you want me to add somebody else to the pypi package as maintainer.

I do not consider the whole PyPi thing a secure solution and thus we do not want to engage us there.

Can you point me to the reasons for this statement. (IMO Pypi is a bit like CTAN or the Debian distribution,
which both can be safe enough or unsafe depending on how you make use of it.)