
Python Package Index
@pypi
Followers
22K
Following
85
Media
42
Statuses
369
The Python Package Index (PyPI) is the repository of software for the Python programming language. Pronounced 🥧 🫛 👁️
The Cloud
Joined September 2017
RT @ThePSF: The PSF has adopted ensuring long-term stability while staying open source and community driven 🎉 Than….
pyfound.blogspot.com
For a little over six years pypistats.org has been maintained and operated by Christopher Flynn on a volunteer basis. After a recent exten...
0
15
0
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python #OpenSource #SupplyChain #Security.
blog.pypi.org
PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over PyPI accounts through password...
0
2
5
The Python Package Index is introducing new restrictions to protect Python package installers and inspectors from ZIP confusion attacks. There is no evidence that this vulnerability has been exploited. Read the blog post for more information:.
blog.pypi.org
PyPI will begin warning and will later reject wheels that contain differentiable ZIP features or incorrect RECORD files.
0
9
31
RT @vortex_ape: i'm late to the party but just started using trusted publishing on @pypi and it's such a nice experience!. just create a re….
0
1
0
"In 2023, Google’s Open Source Security Team (GOSST) helped to fund the launch of Trusted Publishing for PyPI and supported the rollout of 2FA enforcement across PyPI" 👏👏👏.
As we look to the future of open source, we're investing in improving security posture of open source projects and ecosystems. 💡 Learn more about our efforts to secure open source supply chains ⬇️
0
2
7
RT @ThePSF: Astral is starting a fund to support open source projects and maintainers 💝 Thank you @astral_sh for your support of open sourc….
0
19
0
RT @ThePSF: We’re grateful for @fastly’s #FastForward program. With our Fastly-sponsored CDN, in 2023 @pypi had a 99% cache-hit ratio, aver….
0
8
0
RT @ActiveState: Concerned about the security of your Python packages? 🔒 Gain actionable insights and best practices in our upcoming webina….
activestate.com
Dustin Ingram, Fellow at the Python Software Foundation (PSF), joins us to discuss trust and security for PyPI and other repositories in light of recent supply chain attacks, and steps being taken to...
0
4
0
RT @ActiveState: 🎉 ActiveState is pleased to announce our inclusion as a Trusted Publisher to PyPI, enabling Python authors to securely pub….
0
4
0
Starting today, PyPI package maintainers can publish via Trusted Publishing from three additional providers:. - @gitlab .- @googlecloud .- @ActiveState . They join @github Actions to support publishing without long-lived passwords or API tokens.
blog.pypi.org
Announcing additional Trusted Publishing providers
4
35
73
This weekend, we detected & mitigated an account takeover attack affecting several PyPI users. At this time, we have not found evidence of malware or any other malicious activity beyond unauthorized account access. Our incident report has more details.
blog.pypi.org
An attack on PyPI user accounts starting on March 31st, 2024.
1
6
9
PyPI now has an improved way to report #malware, via #PyPI itself! Available on web and preview beta API. Learn more and sign up to help test: .
blog.pypi.org
PyPI now has a new, improved way to report malware.
5
14
34
Looking back at 2023 @mikefiedler discovered some impressive metrics that we want to share! @fastly #PyPI #pytho
2
11
29
TestPyPI ( now requires 2FA for all users to perform management actions. This comes ahead of January 1, 2024 when the same requirement will be applied to all users of PyPI (. Read more at
blog.pypi.org
PyPI requires 2FA for all management actions on TestPyPI.
4
5
15