Open Source Security
PyPI Download Statistics as a Security Signal
PyPI download numbers are noisy, gameable, and widely misused. A closer look at what they actually measure, how to read them for security purposes, and where they break.
Dec 15, 20246 min read