"Lock the Ghost: In the software world, “remove” is not equal to "gone.""

https://www.cert.at/en/blog/2026/3/lock-the-ghost

#pypi #dependencies #supplychain #lockfiles #python

CERT.at - Lock the Ghost

In the software world, “remove” is not equal to "gone." This is crystal clear. There is always a good reason for that. Let’s take a short trip through how Python Package Index handles removals and how we can lock the ghost in an uv.lock file – forever!