#pypi — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Did I just hack up an abomination using xmllint (from libxml2) and jq to query the latest #PyPI version of a package? Perhaps.
Do you no longer have to specify the target version when using pkgbump on PyPI packages? Absolutely.
https://gitweb.gentoo.org/proj/mgorny-dev-scripts.git/tree/bin/get-latest-upstream-version
-
Восемь аниме-плееров рунета изнутри: шифр Цезаря, пустой параметр и домен, который увели
Я взял за основу популярную опенсорсную библиотеку парсеров аниме-плееров, запустил её — и получил от Kodik 500 Internal Server Error . Не «токен протух», не «IP заблокирован», а именно 500 на каждый запрос. Разбор занял вечер, а причина оказалась в одном символе: библиотека отправляла параметр ref пустым, а сервер требует его заполненным и раскодированным . Дальше выяснилось, что это не единичная поломка, а норма жанра. Один плеер полгода назад переехал на другой формат страницы. Другой отвечает бесконечным редиректом на самого себя. У третьего домен просто увели — сейчас там индонезийский интернет-магазин, а не аниме. Четвёртый прячет ссылки в WebSocket из обфусцированного бандла на 600 КБ, и его я честно не осилил. Под катом — разбор восьми плееров: как каждый отдаёт видео, где именно ломаются существующие парсеры и что из этого следует, если вы пишете что-то похожее. Библиотека получилась побочным продуктом и лежит в открытом доступе.
https://habr.com/ru/articles/1079156/
#python #парсинг #реверсинжиниринг #hls #m3u8 #аниме #pypi #github_actions #websocket
-
quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.
https://github.com/christian-korneck/pywinbundle
A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.
-
Watch PSF PyPI Safety & Security Engineer @miketheman's talk from Open Source Summit NA 2026: Trusted Publishing uses OIDC to generate short-lived tokens from CI/CD. No passwords. No tokens to rotate. No secrets in repos.
-
🕵🏻♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.
This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one #GitHub employee's device leads to 3,800 internal repositories exfiltrated — by #TeamPCP, the same group that poisoned 170 npm and #PyPI packages last week. #Grafana gets breached via a token nobody rotated after the TanStack attack, itself a TeamPCP operation. A GitHub Action used by thousands of projects gets compromised and starts exfiltrating CI/CD credentials. And somewhere in a public GitHub spreadsheet, CISA contractor credentials — including #AWS GovCloud keys — sat waiting to be found.
These aren't four separate incidents. They're one incident with four manifestations. The supply chain isn't a vector anymore; it's the terrain. Developer tooling, CI/CD pipelines, third-party actions, tokens issued and forgotten — all of it is now actively mapped and exploited with a persistence that makes the traditional "patch and move on" response look quaint. The Verizon DBIR dropped this week noting that third-party compromise is surging. The week's news was already illustrating the point before the report landed.
→ Week #21/2026 also covers: fast16 predated #Stuxnet and corrupted nuclear simulations quietly, #Pwn2Own Berlin paid $1.3M for 47 bugs, and #Bluesky got hijacked for Russian propaganda.
Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-21-2026-the-supply-chain-didn-t-break-it-was-walked
If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads
#ContagiousInterview #npm #PyPI #Packagist
https://socket.dev/blog/contagious-interview-campaign-spreads-across-5-ecosystems -
A package implementing #AutoCal was published on #PyPI:
🔗 https://pypi.org/project/matchain/
The source sits on #GitHub in a repository administered by the main author of the paper (who is not in the #Fediverse so far):
🔗 https://github.com/ae3000/matchain
Also, there's no implementation in #CommonLisp so far. 😇
4/4
🌺
🏷️ #InstanceMatching #RecordLinkage #OntologyMatching #ArtificialIntelligence #MatChain #WorldAvatar #DigitalTwin #WebSem #LinkedData #KnowledgeGraph #MachineLearning #DeepLearning #Python #Lisp
-
From the abstract:
›We also select an unsupervised state-of-the-art matcher from the field of #DeepLearning for a thorough comparison.
Our results show that neither #AutoCal nor the state-of-the-art matcher is superior regarding matching quality while AutoCal has only moderate hardware requirements and runs 2.7 to 60 times faster.‹
3/4
🌺
🏷️ #InstanceMatching #RecordLinkage #OntologyMatching #ArtificialIntelligence #MatChain #PyPI #WorldAvatar #DigitalTwin #WebSem #LinkedData #KnowledgeGraph
-
From the abstract:
›We introduce #AutoCal, a new #InstanceMatcher which does not require #LabelledData and runs out of the box for a wide range of domains without tuning method-specific parameters.
AutoCal achieves results competitive to recently proposed unsupervised matchers from the field of #MachineLearning.‹
2/4
🌺
🏷️ #InstanceMatching #RecordLinkage #OntologyMatching #ArtificialIntelligence #MatChain #PyPI #WorldAvatar #DigitalTwin #Python #WebSem #LinkedData #KnowledgeGraph
-
May I kindly draw your attention to this scientific paper in the #JournalOfWebSemantics, since my fate was to read many versions of it and to comment extensively:
›A simple and efficient approach to #unsupervised #InstanceMatching and its application to #LinkedData of #PowerPlants‹
→ https://doi.org/10.1016/j.websem.2024.100815
1/4
🌺
🏷️ #MachineLearning #InstanceMatching #RecordLinkage #OntologyMatching #ArtificialIntelligence #AutoCal #MatChain #PyPI #WorldAvatar #DigitalTwin #Python #WebSem #KnowledgeGraph