I found this article unhelpful. While Stufft observes a number of real challenges in the space, at the root thereās a very common philosophy: āif it canāt be perfect, itās not worth it.ā They donāt present a solution, or argue that there isnāt a problem to solve.
Contemporary with this article was the beginning of TUF, which was being developed specifically to address the Python infrastructure - which is a bigger challenge, IMO, than Crates is. Since then, TUF has been adopted as the foundation of Docker Notary. Itās a solid approach that might be able to be applied wholesale.