The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This…
Over the next few months, we will be rolling out changes to the PyPI user interface, improving how we surface…
In 2023 PyPI completed its first security audit, and I am proud to announce that we have now completed our…
This post will drill deeper into two recent supply chain exploits, targeting users of popular PyPI packages - litellm &…
Hello there! I am Maria, the inaugural PyPI Support Specialist. I go by "Thespi-Brain" on GitHub. I wanted to provide…
As 2025 comes to a close, it's time to look back at another busy year for the Python Package Index.…
An attack on the npm ecosystem continues to evolve, exploiting compromised accounts to publish malicious packages. This campaign, dubbed Shai-Hulud,…
We've implemented a new security feature designed to protect PyPI users from phishing attacks: email verification for TOTP-based logins from…
Trusted Publishing has proven popular since its launch in 2023. Recap: Trusted Publishing enables software build platforms to publish packages…
Unfortunately the string of phishing attacks using domain-confusionand legitimate-looking emails continues. This is the same attack PyPI saw a few…
This website uses cookies.