Conversation
…API changes to use staged releases
Documentation build overview
35 files changed ·
|
warsaw
left a comment
There was a problem hiding this comment.
This is a great addition to the PEP. I have some comments for a few things that need clarification, but otherwise +1. And welcome aboard as a co-author!
| **MAY** treat it as though it had completed without an adverse result and publish the session, so that a | ||
| backlogged or unavailable review system does not indefinitely prevent publication. If the review produces an | ||
| adverse result, the session resolves to ``error`` with the reason reported in the session's ``notices``; the | ||
| server **MAY** decline to publish such a session on any subsequent retry, in which case it is eventually |
There was a problem hiding this comment.
This section (if not covered below), should provide details on what happens if files in the session are deleted and reuploaded. It could be:
- Continue to await human review
- Rescan newly uploaded files
- Reset the entire malware scan state
It probably would also be helpful to say something about denial of service attacks on the scanner. E.g. bad actor starts an upload session, uploads known malware knowing it will get flagged. Bad Actor deletes the files and reuploads them to trigger another scan. Rinse and repeat until the scanning service is overwhelmed.
warsaw
left a comment
There was a problem hiding this comment.
I really like this addition to the PEP. It provides a fantastic transition period from legacy to upload-2.0. I have a few questions and suggestions.
…etween legacy and 2.0, minor fixes for other sections.
Amendments based on DPO discussion https://discuss.python.org/t/pre-pep-staged-releases-separated-from-pep-694/107804/59
@warsaw - here are my proprosed amendments which I would like your sign off on as well.