Last week, two versions of litellm package (3.4M downloads/day) contains malicious code due to previous compromise of maintainer's PyPI credentials.
This seems as a cool trick to be less vulnerable to such attacks (found on LinkedIn / Hacker news) 👇
I just discovered Behind the Commit podcast! 🎧 (hosted by Mia Bajić 🎙️)
First two episodes feature Python release managers Hugo van Kemenade (3.14&3.15), Pablo Galindo Salgado (3.10&3.11), Łukasz Langa (3.8&3.9)
and
FastAPI creator Sebastián Ramírez