Guess how angry am I, after trying to package #SigStore (that new NIH signature verification tool that's being pushed through by #CPython, because obviously #PGP is not good enough). Of course, it comes with a ton of random dependencies. Every other has a different build system. Every other has some major issue. Every other comes bringing a ton of more dependencies, including some low quality packages (the kind we removed from #Gentoo, because they were unmaintainable), new NIH crypto libraries (with low test coverage, but security!), unmaintained old dependencies, home-grown frameworks…
But no, if you don't like the Python version (plus Rust, of course), we can alternatively try to Go implementation. After all, vendoring all the dependencies is the best way forward towards security.
[EDIT: did I mention that one package that's had last stable release in 2020, and is in forever beta since?]