We have prohibited new registrations of accounts using inbox.ru email domains.| blog.pypi.org
We responded to an incident related to privileges persisting via Organization Teams after Members are removed from Organizations.| blog.pypi.org
PyPI is formalizing our policies to help us move forward with new services.| blog.pypi.org
Projects on PyPI can now be marked as archived.| blog.pypi.org
Handling project quarantine lifecycle status for suspected malware| blog.pypi.org
Analysis of a package targeted by a supply-chain attack to the build and release process| blog.pypi.org
On 2024-11-21, PyPI was notified about a malware attack with few details.| The Python Package Index Blog
Announcing support for PEP 740 on the Python Package Index| blog.pypi.org
A look back at the past year as the first Safety & Security Engineer for the Python Package Index.| blog.pypi.org
We responded to an incident related to a leaked GitHub Personal Access Token for a PyPI administrator.| blog.pypi.org
Mike Fiedler joins PSF as inaugural PyPI Safety & Security Engineer| blog.pypi.org
This PEP proposes a collection of changes related to the upload and distribution of digitally signed attestations and metadata used to verify them on a Python package repository, such as PyPI.| Python Enhancement Proposals (PEPs)
PyPI has removed support for uploading PGP signatures with new releases.| blog.pypi.org
Publishing to PyPI with a Trusted Publisher| docs.pypi.org