PyPI now serves project status markers in its standard| The Python Package Index Blog
PyPI will begin warning and will later reject wheels that contain differentiable ZIP features or incorrect RECORD files.| blog.pypi.org
Read the follow-up post: Phishing Attack Follow-Up| The Python Package Index Blog
A follow-up to the inbox.ru email domain prohibition.| blog.pypi.org
Follow-up on the recent phishing attack targeting PyPI users.| blog.pypi.org
We have prohibited new registrations of accounts using inbox.ru email domains.| blog.pypi.org
We responded to an incident related to privileges persisting via Organization Teams after Members are removed from Organizations.| blog.pypi.org
PyPI is formalizing our policies to help us move forward with new services.| blog.pypi.org
Projects on PyPI can now be marked as archived.| blog.pypi.org
Handling project quarantine lifecycle status for suspected malware| blog.pypi.org
Analysis of a package targeted by a supply-chain attack to the build and release process| blog.pypi.org
On 2024-11-21, PyPI was notified about a malware attack with few details.| The Python Package Index Blog
Announcing support for PEP 740 on the Python Package Index| blog.pypi.org
A look back at the past year as the first Safety & Security Engineer for the Python Package Index.| blog.pypi.org
We responded to an incident related to a leaked GitHub Personal Access Token for a PyPI administrator.| blog.pypi.org
Announcing additional Trusted Publishing providers| blog.pypi.org
Domain names used in malware attack, and how PyPI handled it.| blog.pypi.org
An attack on PyPI user accounts starting on March 31st, 2024.| blog.pypi.org
The Python Software Foundation is hiring to support PyPI| blog.pypi.org
PyPI now has a new, improved way to report malware.| blog.pypi.org
PyPI now requires 2FA for all users.| blog.pypi.org
PyPI will require 2FA for all users on Jan 1, 2024.| blog.pypi.org
PyPI requires 2FA for all management actions on TestPyPI.| blog.pypi.org
We have prohibited new registrations of accounts using Outlook email domains.| blog.pypi.org
A PyPI user had their account taken over| blog.pypi.org
A deeper dive into the remediation of the security audit findings for the cabotage project.| blog.pypi.org
Analysis of inbound malware reporting volume and response times from PyPI administrators.| blog.pypi.org
GitHub will now scan public repositories' issues for PyPI API tokens, and will notify repository owners when they are found.| blog.pypi.org
PyPI requires new users to enable 2FA before performing management actions.| blog.pypi.org
Mike Fiedler joins PSF as inaugural PyPI Safety & Security Engineer| blog.pypi.org
We are proud to announce PyPI's first external security audit.| blog.pypi.org
PyPI will require all users who maintain projects or organizations to enable one or more forms of two-factor authentication (2FA) by the end of 2023.| blog.pypi.org
The PSF received three subpoenas from the US Department of Justice for PyPI user data in March and April of 2023.| blog.pypi.org
PyPI has removed support for uploading PGP signatures with new releases.| blog.pypi.org
Announcing the launch of a significant new collaboration feature for PyPI| blog.pypi.org
Announcing a new, more secure way to publish to PyPI| blog.pypi.org