/Everyone/ is trying their best, there's always more work to do than there is time for.
I received this email reminder after publishing the latest release of "Truststore" about hardening our publish workflow. This is one of the improvements that PyPI implemented after the Ultralytics supply-chain attack last year to guide folks towards more secure publishing workflows (https://blog.pypi.org/posts/2024-12-11-ultralytics-attack-analysis/).