The #Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of #PyPI projects are compromised.
blog.pypi.org/posts/2026-07-โฆ
#security #supplychain
The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced ๐ฅง ๐ซ ๐๏ธ
- ๐๐ #PyPI has completed its second external #security audit! Thanks to Sovereign Tech Agency for funding, @trailofbits for the audit, and @AlphaOmegaOSS for supporting rapid remediation. Find the full report on the Trail of Bits publication page. #Python
- PSF Security developers have published incident reports on the LiteLLM & Telnyx #supplychain attacks. Read what happened, who's affected, and what developers & maintainers can do to prepare and protect themselves from future incidents. #security #python
- 2025 was another eventful year for PyPI! Critical security enhancements, powerful new org features, a better overall user experience, and transparent security incident response ๐๐ Thank you, PyPI team & community! Learn more on our blog: blog.pypi.org/posts/2025-12-โฆ

