A maintainer temporarily deleted the widely-used atomicwrites library from PyPI to protest PyPI mandating two-factor authentication for top-1% packages. The incident was reminiscent of left-pad and highlighted the tension between registry security mandates and volunteer maintainer autonomy.
SOURCE_SINGLE_CONTRIBUTOR pre-existing; package availability risk
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Partial | SOURCE_SINGLE_CONTRIBUTOR pre-existing; package availability risk |
| Socket | Missed | Not detectable by package scanning |
| Snyk | Missed | No capability for this attack class |
| Sonatype (Nexus) | Missed | No capability for this attack class |
| Black Duck | Missed | No capability for this attack class |
| Endor Labs | Missed | No capability for this attack class |