Re: [RFC] DPT Policy: Canonise recommendation against PyPi-provided upstream source tarballs

On Fri, Jun 25, 2021 at 07:01:39PM -0400, Nicholas D Steeves wrote:
> Does PyPi provide immutable releases?

From experience, I can tell you that yes, releases cannot be overwritten,
but they can be "yanked".  Pypi states that a yanked release is:

  "A release that is always ignored by an installer, unless it is the
  only release that matches a version specifier (using either '==' or

