home.social

Search

1000 results for “pypi”

  1. PyPI now rejects new files after 14 days lwn.net/Articles/1084218/

  2. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

  3. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

  4. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  5. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  6. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  7. The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

    blog.pypi.org/posts/2026-07-22

    #python #security #supplychain #pypi

  8. #PyPI now displays the #Codeberg logo on links pointing there! Looks way better than the generic "external link" icon :BlobCatHeart:

  9. #PyPI now displays the #Codeberg logo on links pointing there! Looks way better than the generic "external link" icon :BlobCatHeart:

  10. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  11. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  12. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  13. Just released multipart-2.0.0 to #pypi.

    This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.

    changelog: multipart.readthedocs.io/en/la

    pypi: pypi.org/project/multipart/

    And when I say 'fast' I mean it: defnull.de/2026/python-multipa

    #SansIO

  14. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  15. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  16. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.

    ep2026.europython.eu/session/a

    #EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security

  17. Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for around this time last year.

    ep2026.europython.eu/session/a

  18. quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.

    github.com/christian-korneck/p

    A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.

    #python #windows #pip #venv #virtualenv #uv #jupyter #pypi

  19. If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow.

    snarky.ca/how-to-publi...

    If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.

    How to publish to PyPI using G...

  20. If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow.

    snarky.ca/how-to-publi...

    If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.

    How to publish to PyPI using G...

  21. TODO: A zero dependency #python app can be installed with

    - git clone
    - or download zip,
    executed with python -m

    But you can't search #pypi for these apps.

  22. This is what collaborative, coordinated, responsible disclosure looks like.
    It was a pleasure to work with GitGuardian on this #PyPI #security investigation to help protect the global #Python #SupplyChain

    blog.gitguardian.com/hunting-l

    Also serves as a reminder to adopt Trusted Publishing whenever possible!
    docs.pypi.org/trusted-publishe

  23. This is what collaborative, coordinated, responsible disclosure looks like.
    It was a pleasure to work with GitGuardian on this #PyPI #security investigation to help protect the global #Python #SupplyChain

    blog.gitguardian.com/hunting-l

    Also serves as a reminder to adopt Trusted Publishing whenever possible!
    docs.pypi.org/trusted-publishe