This is for making “pip install” safer, so that dependencies of your packages cannot change under your feet.
However, keep in mind that third-party PyPi packages are not vetted or reviewed for security before they become available. So, they are subject to the same risks for compromise as Arch Linux AUR packages.
A safer alternatve would be to use GNU Guix, which has vetted packages, builds everything transparently from source, and has great support for cross-language projects.
What’s also worth mentioning is that Guix packages are also an excellent way to distribute new FLOSS software for Linux/POSIX - your packages do not need to be part of the Guix distribution.
You can just put your package definition on your Codeberg or github page and users can pull that. Pretty much like Ubuntu PPAs or flatpaks but since everything is defined from source, people can inspect what they get, which fosters trust.
And it works for any distro that works with Guix, without modification, because the Guix dependencies give a 100% reproducible base.