An attack on the npm ecosystem continues to evolve, exploiting compromised accounts to publish malicious packages. This campaign, dubbed Shai-Hulud,…
We've implemented a new security feature designed to protect PyPI users from phishing attacks: email verification for TOTP-based logins from…
Trusted Publishing has proven popular since its launch in 2023. Recap: Trusted Publishing enables software build platforms to publish packages…
We are pleased to announce the release of the new Expense Submission flow! 🎉We’ve done a lot to increase the…
Unfortunately the string of phishing attacks using domain-confusionand legitimate-looking emails continues. This is the same attack PyPI saw a few…
SummaryI recently responded to an attack campaign where malicious actors injected code into GitHub Actions workflows attempting to steal PyPI…
SummaryPyPI now checks for expired domains to prevent domain resurrection attacks,a type of supply-chain attack where someone buys an expired…
PyPI now serves project status markers in its standardindex APIs. This allows downstream consumers (like Python package installers andindex mirrors)…
Providing insight into our product roadmap and, subsequently, the projects being worked on in our six-week cycles. Â We've been working…
You can now subscribe to your favorite collectives' updates using RSS feeds! RSS is an open standard that lets you…
This website uses cookies.