Metadata-Version: 2.4
Name: amazon-ascs
Version: 0.0.1
Summary: Placeholder registered as proof-of-concept for a security report filed with Amazon's Vulnerability Research Program. Not affiliated with Amazon. Performs no operations.
License: MIT
Project-URL: Homepage, https://developer.supplychain.amazon.com/
Keywords: placeholder,security-poc,avrp
Classifier: Development Status :: 7 - Inactive
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: MIT License
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Security
Requires-Python: >=3.7
Description-Content-Type: text/markdown

# amazon-ascs (placeholder)

This PyPI package name is a placeholder registered as proof of concept for a security report
filed with Amazon's Vulnerability Research Program.

It is **not affiliated with Amazon** and it performs **no operations**. Installing it does
not run any code, does not import anything at install time, and does not connect to any
network endpoint.

## Why does this exist?

At the time of registration, Amazon's ASCS Developer Portal at
`https://developer.supplychain.amazon.com/` instructs external supply chain integrators to
run `pip install amazon-ascs` in its "Install the SDK" step, but Amazon had not registered
that name on public PyPI. Any first-come account could have claimed it and shipped arbitrary
code to every developer following those instructions. This placeholder was registered to
prevent that outcome while Amazon reviews the report and takes ownership of the name.

## If you are an Amazon supply chain integrator

Do not use this package. It has no functionality. The official Amazon SDK, when Amazon
publishes it, will come from an Amazon-owned PyPI account with real metadata and code.
Please contact Amazon supply chain support for the official SDK.

## For Amazon

This package name will be transferred to Amazon's ownership on request, at no cost.
