-
Notifications
You must be signed in to change notification settings - Fork 49
Description
PyPI user performing the mass project name squatting
https://pypi.org/user/adminlrh
Additional information
Greetings--
All 28 packages provided by the adminlrh account are virtually identical and provide no functionality. According to their descriptions:
It contains a simple function hello() that returns a greeting string.
I've investigated many of these package names and discovered that they were referenced by other projects on GitHub, but were not published on PyPI. Instead, many of the sources for these packages are on GitHub, provided on external indexes, or are typos.
I discovered this after finally trying to publish my package https://github.com/mborgerson/bintrace to PyPI, which had been installable from only from source on GitHub for a while.
- sphinx-pydata-theme - https://github.com/pydata/pydata-sphinx-theme/blob/main/pyproject.toml
- rqdatac-bond - https://pypi.org/project/rqdatac
- robotpy-opencv - https://github.com/robotpy/roborio-opencv
- loopstructuralviusualisation - https://github.com/Loop3D/LoopStructural/blob/d40a0e92eef7f1306160f0542a04e49f61577e31/pyproject.toml#L45
- latent-diffusion - https://github.com/CompVis/latent-diffusion/blob/main/setup.py
- ipyprogress - https://github.com/AnswerDotAI/rerankers/blob/6a65126a68465135d4d86f95fc245e2d6fe41f90/pyproject.toml#L77
- bintrace - https://github.com/mborgerson/bintrace/blob/master/pyproject.toml
- pyscf-shciscf - https://github.com/pyscf/shciscf/blob/master/setup.py
- dagster-cloud-backend - https://github.com/dagster-io/dagster-cloud/blob/4d52e04dd0bc729df33f20b2017a14510f6c204b/dagster-cloud/pyproject.toml#L85
- dagster-cloud-test-infra - https://github.com/dagster-io/dagster-cloud/blob/4d52e04dd0bc729df33f20b2017a14510f6c204b/dagster-cloud/pyproject.toml#L78
- zlgcan-driver-py - https://github.com/jesses2025smith/zlgcan-driver
A number of dependencies required for modelscope in https://github.com/modelscope/modelscope/blob/master/requirements/cv.txt (and other requirement files therein) are served out of https://modelscope.oss-cn-beijing.aliyuncs.com/releases/ including:
- ttsfrd
- kantts
- videofeatures-clipit
- MinDAEC - https://github.com/modelscope/modelscope/blame/8f3e1845d243bdf6f78026379fa83ed6bab91f2e/docker/Dockerfile.ubuntu#L49
- kwsbp
- megatron-util
- shotdetect-scenedetect-lgss
- ddpm-guided-diffusion
- bmt-clipit
- paint-ldm
- control-ldm
- py-sound-connect
I hope you will consider the evidence of this account's noncompliance with PyPI's name squatting policy and remove these packages from the index. Thank you for your time.
Code of Conduct
- I agree to follow the PSF Code of Conduct