Search
1000 results for “pypi”
-
PyPI now rejects new files after 14 days https://lwn.net/Articles/1084218/
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.
https://github.com/christian-korneck/pywinbundle
A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.
-
If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow.
snarky.ca/how-to-publi...
If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.
How to publish to PyPI using G... -
If you use GitHub Actions to publish to #PyPI, I wrote a blog post outlining what I consider the key things you can do to secure your publishing workflow.
snarky.ca/how-to-publi...
If you don't use GitHub Actions for publishing, this post will NOT be of interest to you.
How to publish to PyPI using G... -
This is what collaborative, coordinated, responsible disclosure looks like.
It was a pleasure to work with GitGuardian on this #PyPI #security investigation to help protect the global #Python #SupplyChainhttps://blog.gitguardian.com/hunting-leaked-pypi-tokens-62-live-125-packages-exposed/
Also serves as a reminder to adopt Trusted Publishing whenever possible!
https://docs.pypi.org/trusted-publishers/ -
This is what collaborative, coordinated, responsible disclosure looks like.
It was a pleasure to work with GitGuardian on this #PyPI #security investigation to help protect the global #Python #SupplyChainhttps://blog.gitguardian.com/hunting-leaked-pypi-tokens-62-live-125-packages-exposed/
Also serves as a reminder to adopt Trusted Publishing whenever possible!
https://docs.pypi.org/trusted-publishers/