Incident Report: File Hosting Errors
Executive summary For about two weeks in August 2026, some PyPI users hit intermittent 502 and 503 errors downloading files from files.pythonhosted.org, triggering failures during installation from PyPI. Thanks to our users filing reports in the support tracker; one report in particular narrowed the problem to a single cache node.Continue Reading
Metadata requests no longer tracked in PyPI download counts
On 2026-08-24 I shipped a change to the configuration that emits PyPI’s download logs so that only requests for actual distribution artifacts are counted. A request has to end in .whl, .tar.gz, or .zip to produce a download record. The counts are more accurate now, and existing systems based onContinue Reading
How AWS Powers PyPI and the PSF
Working on infrastructure at the Python Software Foundation (PSF) as the Director of Engineering is a broad job with many hats. Python turns up everywhere. It’s in healthcare systems and government agencies, in research labs and classrooms, in one-person side projects and in infrastructure at companies with six-figure headcounts. SomebodyContinue Reading
The HTML representation of the index API is now frozen
PyPI has adopted PEP 833, which “freezes” the HTML representation of the index API, which is also sometimes called the “simple API” or the “simple repository API.” New packages and releases will continue to appear in the HTML representation, meaning this has no breaking implications for downstream index consumers. However,Continue Reading
Releases now reject new files after 14 days
The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised. As far as we areContinue Reading
Planned Updates to the PyPI User Interface
Over the next few months, we will be rolling out changes to the PyPI user interface, improving how we surface security signals and updating the pages where users view package details. Updates will be staged to TestPyPI and deployed to production in phases. This approach allows our team to thoroughlyContinue Reading
Release: Sidebar Reorganization – Part 3 – “The Switch”
Highlighting the next stage in our sidebar reorganization campaign! We are still primarily focusing on Organization Dashboards (which have the highest financial complexity) and gradually introducing changes to individual and collective dashboards. As a reminder, the intention behind this redesign is to make the platform more coherent, intuitive, and welcoming,Continue Reading
SMS Email Gateway List
Source: SMS Email Gateway ID Provider Country Email Format Notes Id Provider Country Email Address Format Notes 1 Bluesky Communications American Samoa #######@psms.bluesky.as 2 CTI Movil Argentina ##########@sms.ctimovil.com.ar 3 Movistar Argentina ##########@sms.movistar.net.ar 4 Nextel Argentina ##########@TwoWay.11nextel.net.ar 5 Setar Aruba 297##########@mas.aw 6 Optus Mobile Australia 0##########@optusmobile.com.au 7 Telstra Australia ##########@online.telstra.com.au 8Continue Reading
PyPI has completed its second audit
In 2023 PyPI completed its first security audit, and I am proud to announce that we have now completed our second external security audit. This work was funded by the Sovereign Tech Agency, a supporter of Open Source security-related improvements, partnering with Trail of Bits to perform the audit. ThanksContinue Reading
Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance
This post will drill deeper into two recent supply chain exploits, targeting users of popular PyPI packages – litellm & telnyx. We also provide Python developers and maintainers with guidance on what they can do to prepare and protect themselves from future incidents. What happened with LiteLLM and telnyx? AfterContinue Reading





